TinyShell is a lightweight Unix-family backdoor that has been repeatedly adapted for long-term covert access on Linux, Solaris, Junos OS, and network appliances. It is publicly available in open-source form, but multiple threat actors have customized it into distinct variants with different command-and-control methods, active and passive modes, and platform-specific persistence mechanisms. Across observed intrusions, TinyShell has been used to establish outbound command-and-control channels, maintain stealthy persistence, and provide remote shell access after initial compromise.
TinyShell has been associated with several notable intrusion sets. UNC2891, also tracked as LightBasin in related reporting, used TinyShell in financially motivated operations against banking infrastructure, including ATM-switching environments and Solaris systems. In those cases it was used to maintain persistent access, including through outbound communications over mobile data and dynamic DNS after a physical implant provided internal network access. UNC3886, a China-nexus espionage actor, deployed multiple custom TinyShell-based backdoors on end-of-life Juniper MX routers running Junos OS, including variants designed for stealth and long-term persistence and accompanied by logging-disabling functionality. UNC4540 used a TinyShell variant on unpatched SonicWall SMA appliances as part of a malware suite focused on credential theft, shell access, and persistence across firmware upgrades. Red Menshen has also used TinyShell as a passive persistence mechanism and staging backdoor during telecom espionage operations.
Observed TinyShell deployments show broad post-compromise utility. It has been used to create persistent command channels, support lateral movement from staging systems, and retain fallback access on internet-facing infrastructure. In some campaigns it was paired with credential-harvesting tools such as keyloggers and brute-force utilities, while in appliance-focused compromises it was launched by scripts or companion malware that ensured restart and survival across updates. On Junos devices, reporting describes as many as six distinct TinyShell variants in a single campaign, reflecting substantial customization for evasion and operational resilience.
TinyShell primarily targets Unix-like environments rather than end-user systems. Confirmed platforms include Linux and Oracle Solaris servers, Junos OS-based routers, and Linux-based security appliances such as SonicWall SMA devices. Victim sectors linked to TinyShell activity include banking and payment infrastructure, telecommunications, and organizations operating critical network edge or management systems. Its repeated use by both financially motivated and state-linked actors underscores its value as a compact, flexible backdoor for stealthy persistence and remote administration in high-value infrastructure environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Juniper vydala bezpečnostné aktualizácie pre svoj sieťový operačný systém Junos OS, ktoré opravujú aktívne zneužívanú zraniteľnosť. CVE-2025-21590 by lokálny útočník s prístupom k shell-u mohol zneužiť na obídenie bezpečnostného mechanizmu Veriexec, vykonanie škodlivého kódu a získanie úplnej kontroly nad systémom. | Zariadenia sú infikované až 6 variantmi open-source backdooru TinyShell. Každý variant na maskovanie svojej činnosti používa iné C2 a inú metódu riadiacej komunikácie.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Other tools linked to the actor in previous attacks include Slapstick, Tinyshell, Steelhound, Steelcorgi, Wingjook, Wingcrack, Binbash, Wiperight, and the Mignogcleaner, all of which Mandiant confirmed as still deployed in LightBasin attacks.
Mandiant has documented the activities of a team it's called UNC2891 and its targeting of Solaris systems with backdoors dubbed TINYSHELL and SLAPSTICK and a rootkit called CAKETAP.
Zariadenia sú infikované až 6 variantmi open-source backdooru TinyShell. Každý variant na maskovanie svojej činnosti používa iné C2 a inú metódu riadiacej komunikácie.
Common Patterns Across Intrusions Analysis of both intrusion sets, along with additional intelligence from other affected operators in this campaign, identified the following consistent patterns: TinyShell and China Chopper were both used to establish persistence on staging systems during lateral movement.
The malware used on SonicWall devices consists of an ELF binary, the TinyShell backdoor, and several bash scripts that show a deep understanding of the targeted network devices.
Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
A suspected Chinese hacking campaign has been targeting unpatched SonicWall Secure Mobile Access (SMA) appliances... While it is unclear what vulnerability was used to compromise devices, Mandiant says that the targeted devices were unpatched, making them likely vulnerable to older flaws.
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
TinyShell and China Chopper were both used to establish persistence on staging systems during lateral movement.
"In March 2025, it was revealed that Chinese cyber-espionage actors were deploying custom backdoors on EoL Junos OS MX routers to drop a set of ‘TinyShell’ backdoor variants."
Nesprávne overovanie pôvodu súborov a nedostatočnú izoláciu procesov možno injekciou kódu do legitímnych procesov zneužiť na obídenie zabudovaného bezpečnostného mechanizmu Veriexec.
CVE-2025-21590 by lokálny útočník s prístupom k shell-u mohol zneužiť na obídenie bezpečnostného mechanizmu Veriexec, vykonanie škodlivého kódu a získanie úplnej kontroly nad systémom.
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
Mandiant has documented the activities of a team it's called UNC2891 and its targeting of Solaris systems with backdoors dubbed TINYSHELL and SLAPSTICK and a rootkit called CAKETAP.
the backdoor process, which was named “lightdm” in an attempt to masquerade as the legitimate LightDM display manger, but was found at an unusual location
Backdoor named lightdm with legitimate-looking arguments, run from /tmp and /var/snap/.snapd.
Nesprávne overovanie pôvodu súborov a nedostatočnú izoláciu procesov možno injekciou kódu do legitímnych procesov zneužiť na obídenie zabudovaného bezpečnostného mechanizmu Veriexec.
These backdoors included active and passive functions, and embedded scripts that disabled logging mechanisms on the device.
Also dropped are Sliver, TinyShell, keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
The broadly-connected network monitoring server was used as a pivot; a secondary backdoor on the internet-facing mail server maintained access.
where the BPFdoor controller was deployed... The BPFdoor backdoor was deployed on these systems for long-term persistence.
Additionally, firewalld launches other malware components, like TinyShell, to establish a reverse shell on the appliance for easy remote access.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor used by UNC2891 for outbound command-and-control over 4G/mobile data, providing persistent remote access from the implanted Raspberry Pi and related footholds.
A custom backdoor family used by UNC3886 on Junos OS routers, including active and passive backdoor functions and embedded scripts that disabled logging mechanisms on the device to support stealth and persistence.
A backdoor used to establish persistence on staging systems during lateral movement as part of the broader telecom intrusion campaign.
A backdoor used to establish outbound C2 access from the compromised ATM network via Dynamic DNS, enabling persistent remote access and bypassing perimeter defenses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.