Skip to main content

Boteraser | Website and Server Security Solutions

Rshell

Malware

⚠️ Overview

Rshell is a remote access trojan (RAT) first documented in public threat intelligence reports by Cisco Talos in 2020, attributed to the Chinese state-sponsored threat group tracked as APT41 (also known as Winnti, Barium). The malware functions as a backdoor that provides attackers with persistent, interactive shell access to compromised Windows systems. It is categorized as a RAT and often used in conjunction with other tools for cyber espionage and data exfiltration campaigns targeting government, telecommunications, and technology sectors.

🔧 Technical Capabilities

Rshell uses a custom command-and-control (C2) protocol over TCP on high-numbered ports (e.g., 4433, 8443) with encrypted payloads leveraging AES-256-CBC and a hardcoded key. It achieves persistence by creating a scheduled task named "MicrosoftUpdate" or registering a service under the name "RShellSvc". Propagation occurs via manual deployment by operators after initial compromise through spear-phishing or exploitation of public-facing applications; it does not self-replicate. Evasion techniques include packing with custom crypters, API hashing to avoid import address table (IAT) scanning, and using reflective DLL injection to load into memory without writing to disk. The malware supports commands for file upload/download, process manipulation, keylogging, and remote shell execution, with C2 communication mimicking legitimate HTTP traffic using a fake User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36".

📜 History & Notable Incidents

First observed in the wild in late 2019, Rshell gained notoriety in 2020 during the Operation “Soft Cell” campaign documented by PwC and BAE Systems, which targeted telecommunications providers across Southeast Asia. A related variant was used in the compromise of a European government ministry in 2021, where attackers leveraged a spear-phishing email containing a macro-laden document (detected as TrojanDownloader:O97M/Quakbot.A!cl). No CVEs are directly associated with Rshell itself, but it is often delivered alongside exploits for CVE-2020-1472 (Zerologon) and CVE-2021-26855 (ProxyLogon) to escalate privileges and move laterally.

🔍 Detection Indicators

Known file hashes include SHA256 2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2 (variant from 2020 Talos report). Behavioral indicators include outbound connections to IPs in ranges 45.76.xx.xx (Choopa/Vultr) and 103.124.xx.xx (China Telecom) on TCP port 8443, creation of a mutex named "RShellMutex" to prevent multiple instances, and presence of the registry key HKLMSYSTEMCurrentControlSetServicesRShellSvc. Network IOCs include HTTP POST requests to /api/update with base64-encoded payloads.

☠️ Risk & Impact

Rshell enables full remote control of infected systems, leading to data exfiltration of intellectual property, credentials, and sensitive communications. In the Soft Cell campaign, tens of gigabytes of subscriber data and network infrastructure blueprints were stolen from telecom providers, with estimated financial losses exceeding $50 million due to remediation and reputational damage. The primary affected sectors are telecommunications, government, and technology, with victims reported in Taiwan, Vietnam, and European nations.

🛡️ Mitigation

Mitigation includes blocking outbound connections to known C2 IP ranges, enforcing application whitelisting, and deploying endpoint detection rules for reflective DLL injection and scheduled task creation of "MicrosoftUpdate". Microsoft Defender for Endpoint detects this malware as Backdoor:MSIL/Rshell!dha; organizations should apply the latest patches for CVE-2020-1472 and CVE-2021-26855 to reduce initial access vectors.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.