FILTERING BY: CLEAR FILTER

BlackTech APT Deploys BlueShell Linux Backdoor

BlackTech, a specialized cyberespionage APT, has launched a targeted campaign against Japanese organizations utilizing the BlueShell Linux backdoor. After gaining initial network access, the actor deploys BlueShell to maintain persistence by masquerading as a legitimate kernel worker process, effectively evading standard administrative detection. The malware provides a robust remote-access toolkit, supporting remote command execution (RCE), file exfiltration, and internal network traffic routing. These capabilities allow the threat actor to pivot through internal systems, facilitating advanced lateral movement and long-term espionage within sensitive Linux-based infrastructures.


LINK COPIED TO CLIPBOARD