Emergence of TencShell malware leveraging open-source Rshell framework in targeted campaign against global manufacturer
Summary
Hide ▲
Show ▼
China-linked threat actors deployed a previously undocumented malware implant named TencShell against a global manufacturer’s Indian branch in April 2026. The attack chain involved a first-stage dropper, Donut shellcode, a masqueraded .woff web-font resource, memory injection, and web-like C2 communication to deliver a customized Go-based implant derived from the open-source Rshell C2 framework. TencShell mimics Tencent-like web service paths to blend into normal enterprise traffic. If successful, the implant would have provided comprehensive access, including remote command execution, in-memory payload execution, proxying, pivoting, system profiling, and a path to deploy additional tooling.
Timeline
-
15.05.2026 11:00 1 articles · 2h ago
New TencShell malware implant deployed via open-source Rshell framework in targeted campaign
A previously undocumented malware implant named TencShell was deployed against a global manufacturer’s Indian branch in April 2026. The attack chain utilized a first-stage dropper, Donut shellcode, and a masqueraded .woff web-font resource to deliver a customized Go-based implant derived from the open-source Rshell C2 framework. The implant mimics Tencent-like web service paths for C2 communication, enabling comprehensive access including remote command execution, in-memory payload execution, and system profiling if successfully deployed.
Show sources
- China-Linked Hackers Deploy New TencShell Malware Against Global Manufacturer — www.infosecurity-magazine.com — 15.05.2026 11:00
Information Snippets
-
Threat actor leveraged a first-stage dropper, Donut shellcode, a masqueraded .woff web-font resource, memory injection, and web-like C2 communication to deliver the TencShell implant.
First reported: 15.05.2026 11:001 source, 1 articleShow sources
- China-Linked Hackers Deploy New TencShell Malware Against Global Manufacturer — www.infosecurity-magazine.com — 15.05.2026 11:00
-
TencShell is a customized Go-based implant derived from the open-source Rshell C2 framework, repackaged for this operation.
First reported: 15.05.2026 11:001 source, 1 articleShow sources
- China-Linked Hackers Deploy New TencShell Malware Against Global Manufacturer — www.infosecurity-magazine.com — 15.05.2026 11:00
-
The implant mimics Tencent-like web service paths in its C2 communication to blend into enterprise traffic.
First reported: 15.05.2026 11:001 source, 1 articleShow sources
- China-Linked Hackers Deploy New TencShell Malware Against Global Manufacturer — www.infosecurity-magazine.com — 15.05.2026 11:00
-
TencShell provides remote command execution, in-memory payload execution, proxying, pivoting, system profiling, and a path to deploy additional tooling if deployed successfully.
First reported: 15.05.2026 11:001 source, 1 articleShow sources
- China-Linked Hackers Deploy New TencShell Malware Against Global Manufacturer — www.infosecurity-magazine.com — 15.05.2026 11:00
-
The campaign targeted the Indian branch of an unnamed global manufacturer in April 2026.
First reported: 15.05.2026 11:001 source, 1 articleShow sources
- China-Linked Hackers Deploy New TencShell Malware Against Global Manufacturer — www.infosecurity-magazine.com — 15.05.2026 11:00