TinyShell is a lightweight, open-source backdoor used to maintain remote access to Unix-like servers and network appliances. It supports interactive command execution, reverse shells, and file uploads and downloads, enabling operators to administer compromised hosts, transfer tools, and retrieve data. Deployments include Linux systems, Oracle Solaris servers, SonicWall Secure Mobile Access appliances, and Juniper MX routers running Junos OS.
Operators have configured TinyShell implants to connect between compromised internal servers and externally reachable systems, creating chained access paths within enclosed networks. In UNC2891 banking intrusions, TinyShell provided persistent access across internal servers and internet-facing mail infrastructure. Some deployments used cellular connectivity through a physically implanted Raspberry Pi to bypass perimeter firewalls. Operators disguised TinyShell processes as legitimate services and concealed their process information using Linux bind mounts, hindering conventional process and network inspection.
TinyShell has been used by financially motivated and espionage actors, including UNC2891, UNC1945, LIMINAL PANDA, UNC3886, and Red Menshen. Documented targets include banking and ATM infrastructure and telecommunications networks. UNC3886 deployed six customized TinyShell variants on end-of-life Juniper MX devices, using different command-and-control configurations and both active and passive backdoor functionality. In UNC4540 operations against SonicWall appliances, TinyShell supplied reverse-shell access within a broader malware suite whose separate scripts stole credential hashes and preserved the infection through firmware upgrades. TinyShell functionality is also incorporated into BPFDoor variants to provide interactive shells and file transfers after activation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Juniper vydala bezpečnostné aktualizácie pre svoj sieťový operačný systém Junos OS, ktoré opravujú aktívne zneužívanú zraniteľnosť. CVE-2025-21590 by lokálny útočník s prístupom k shell-u mohol zneužiť na obídenie bezpečnostného mechanizmu Veriexec, vykonanie škodlivého kódu a získanie úplnej kontroly nad systémom. | Zariadenia sú infikované až 6 variantmi open-source backdooru TinyShell. Každý variant na maskovanie svojej činnosti používa iné C2 a inú metódu riadiacej komunikácie.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign uses malware consisting of bash scripts and an Executable and Linkable Format binary that Mandiant identified as a TinyShell backdoor.
TinyShell is listed alongside TinyFluff, TinyPosh, and TinyNode among the four implants used by OldGremlin.
To maintain access to hosts within enclosed networks, TINYSHELL was deployed on multiple servers and configured to connect to other servers within the same network.
To maintain access to hosts within enclosed networks, TINYSHELL was deployed on multiple servers and configured to connect to other servers within the same network.
Откако ќе се активира, примерокот на BPFDoor започнува TinyShell сесија и поддржува команди за интерактивна shell околина, како и можности за прикачување и преземање датотеки.
Откако ќе се активира, примерокот на BPFDoor започнува TinyShell сесија и поддржува команди за интерактивна shell околина, како и можности за прикачување и преземање датотеки.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
A suspected Chinese hacking campaign has been targeting unpatched SonicWall Secure Mobile Access (SMA) appliances... While it is unclear what vulnerability was used to compromise devices, Mandiant says that the targeted devices were unpatched, making them likely vulnerable to older flaws.
The threat actor was also observed persisting with TINYSHELL via init scripts and service creation.
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
TinyShell and China Chopper were both used to establish persistence on staging systems during lateral movement.
Mandiant explained ... it discovered the UNC3886 “China-nexus espionage group” had deployed several TINYSHELL-based backdoors into Junos OS-powered routers.
These services were registered with systemd to achieve persistence, allowing them to automatically execute during system startup and reboot.
The threat actor was also observed persisting with TINYSHELL via init scripts and service creation.
Nesprávne overovanie pôvodu súborov a nedostatočnú izoláciu procesov možno injekciou kódu do legitímnych procesov zneužiť na obídenie zabudovaného bezpečnostného mechanizmu Veriexec.
CVE-2025-21590 by lokálny útočník s prístupom k shell-u mohol zneužiť na obídenie bezpečnostného mechanizmu Veriexec, vykonanie škodlivého kódu a získanie úplnej kontroly nad systémom.
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
Mandiant explained ... it discovered the UNC3886 “China-nexus espionage group” had deployed several TINYSHELL-based backdoors into Junos OS-powered routers.
Mandiant has documented the activities of a team it's called UNC2891 and its targeting of Solaris systems with backdoors dubbed TINYSHELL and SLAPSTICK and a rootkit called CAKETAP.
STEELCORGI is a packer used to encrypt malware used by the attackers.
the backdoor process, which was named “lightdm” in an attempt to masquerade as the legitimate LightDM display manger, but was found at an unusual location
The threat actor disguised deployed malware with legitimate-looking names.
Nesprávne overovanie pôvodu súborov a nedostatočnú izoláciu procesov možno injekciou kódu do legitímnych procesov zneužiť na obídenie zabudovaného bezpečnostného mechanizmu Veriexec.
These backdoors included active and passive functions, and embedded scripts that disabled logging mechanisms on the device.
Also dropped are Sliver, TinyShell, keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
The broadly-connected network monitoring server was used as a pivot; a secondary backdoor on the internet-facing mail server maintained access.
where the BPFdoor controller was deployed... The BPFdoor backdoor was deployed on these systems for long-term persistence.
Additionally, firewalld launches other malware components, like TinyShell, to establish a reverse shell on the appliance for easy remote access.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote shell tooling incorporated into the reported BPFDoor sample to provide interactive command execution and file uploads and downloads. The article also notes prior use by China-linked clusters targeting telecommunications networks and edge devices.
Shell-access tool integrated into an observed BPFDoor sample to provide interactive command execution and file upload/download capabilities. The article separately notes its previous use by several China-nexus threat clusters; those historical associations do not establish attribution for the current campaign.
A TINYSHELL component was listed among Fire Ant intrusion artifacts.
A backdoor used by UNC2891 for outbound command-and-control over 4G/mobile data, providing persistent remote access from the implanted Raspberry Pi and related footholds.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.