Skip to content

RedShell

RedShell is a native Linux implant associated with the RedC2 4.0 command-and-control framework.

Profile source: Mallory opens in a new tab

RedShell

Family profile

RedShell is a native Linux implant associated with the RedC2 4.0 command-and-control framework. It functions as a post-exploitation backdoor and beacon, providing remote operators with interactive shell access, command execution, file operations, host and network reconnaissance, data collection, and network pivoting capabilities. Documented functionality includes theft of SSH keys, browser-stored credentials, and database-related files; reverse shell access; file transfer; SOCKS5 proxying; TCP port forwarding; tunneling; persistence through cron, shell startup files, user-level services, and desktop autostart mechanisms; and in-memory execution of ELF payloads and shellcode. The implant also gathers host metadata such as user, hostname, operating system details, network information, and privilege context before entering its command-processing loop.

RedShell has been observed delivered through software supply-chain compromises involving trojanized npm packages masquerading as legitimate date, calendar, and streak-calculation utilities. In these cases, the malicious packages preserved advertised functionality while using the module entry point to silently make an embedded Linux ELF payload executable and launch it as a detached background process when the package was imported, including via transitive dependencies. This execution path did not depend on npm lifecycle hooks, increasing the likelihood of unnoticed compromise in developer and build environments. The malware is positioned to expose source code, deployment secrets, cloud access, and internal services reachable from trusted Linux hosts.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 10, 2026
Last activity
Sep 10, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • US1

Leading providers

  • Miteflux Technologies Ltd1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
MarlboroMan

It's located either directly within the "dist/" or under "dist/internal/," but what it contains is the same: the RedShell Linux beacon for RedC2 4.0 that communicates with a remote Windows or Linux server to facilitate post-exploitation activities on the compromised host.

MITRE ATT&CK

RedShell in ATT&CK

37 distinct techniques

Reporting

Research mentioning RedShell

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.