Tool
VShell
- First Reported
- Jul 14, 2026
- Latest Reported
- Jul 23, 2026
Reported Context (2)
- identified as high risk due to the historical presence of a ShadowPad controller, and currently hosting a VShell C2 server on port 21083. A single domain, redhatupdating432.dnsrd[.]com resolves to the server, though Unattended Hermes AI Agent Used in Targeting of Thailand Finance Ministry, Researchers Find
- the server was flagged as high risk for exposing Asset Reconnaissance Lighthouse (ARL) and a Vshell C2 service. Hunt.io Details Suspected China-Linked Campaign Using Claude Code and DeepSeek Against Government Systems
CVE (7)
Malware (4)
People (1)
MITRE ATT&CK (20)
Vendors (5)
Products (15)
Tools (12)
Industries (7)
Countries (8)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.