FRUITSHELL is a publicly available PowerShell reverse shell for Windows, first observed in January 2025 and subsequently observed in active operations. It establishes an outbound TCP connection to a configured command-and-control server, receives commands, executes them through PowerShell's Invoke-Expression, and returns command output over the connection. Its connection parameters are reconstructed from obfuscated, fruit-named variables. The original script implements no persistence, staging, or privilege escalation.
FRUITSHELL's distinctive feature is an execution-inert comment intended to manipulate LLM-assisted security analysis. The comment instructs AI analyzers not to examine the script and falsely characterizes its purpose as benign prime-number generation. This is a prompt-injection attempt against analysis pipelines, not a runtime AI capability: FRUITSHELL neither calls an LLM nor uses AI to generate commands or modify itself. The technique does not interfere with conventional antivirus detection.
The same or similar anti-analysis comment has appeared in independently developed scripts associated with multiple unrelated operators. Its reuse does not establish FRUITSHELL family membership, and capabilities such as AMSI bypass and shellcode loading found in those other scripts are not features of the original FRUITSHELL reverse shell.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
There were no new MITRE attack techniques. Seven of eight operations ran T1059, Command & Scripting Interpreter, the single most ordinary technique in the framework.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PowerShell reverse shell using fruit-named variables for obfuscation. It embeds comments instructing AI analyzers to skip analysis and falsely describing its functionality as prime-number generation. These comments do not affect execution; they target AI-assisted analysis pipelines.
PowerShell reverse shell using obfuscated fruit-named variables. It embeds a plaintext comment instructing AI analyzers to skip analysis and falsely claiming that the script generates prime numbers. The comment does not affect execution; it targets AI-assisted analysis pipelines. Its evasion text was subsequently copied into independent scripts.
PowerShell reverse shell that embeds prompts intended to bypass LLM-based security analysis.
Reverse shell malware engineered to evade or bypass AI-assisted security controls/detections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.