Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The HTTPService.dll and HTTPApi.dll samples documented by Elastic Security Labs as SHELBYLOADER and SHELBYC2 ... are classified as HOTAIR and AEROSTAT and associated with UNC5795. | RuntimeBroker.dll collected host metadata and registered the system through myLic. The operator could then decide whether to provide host-specific activation material.
RuntimeBroker.dll collected host metadata and registered the system through myLic. The operator could then decide whether to provide host-specific activation material.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Both the loader and backdoor are obfuscated with the open-source tool Obfuscar, which employs string encryption as one of its features.
The malware generates an AES key and initialization vector (IV) from the contents of License.txt... It proceeds to decrypt the file HTTPApi.dll, which contains the backdoor payload.
License.txt... is uploaded by the attacker’s backend only after validating that the malware is not running in a sandbox environment. This ensures only validated infections receive the key and escalate the execution chain to the backdoor.
SHELBYLOADER utilizes sandbox detection techniques to identify virtualized or monitored environments.
SHELBYLOADER utilizes sandbox detection techniques to identify virtualized or monitored environments... WMI Query for System Information... Process Enumeration... File System Checks... Disk Size Analysis... Parent Process Verification... WMI Query for Video Controller.
The data used to create the hash is formatted as follows... The domain name associated with the user account. The username of the currently logged-in user.
The malware scans the running processes for known virtualization-related services, including: vmsrvc vmtools xenservice vboxservice vboxtray.
First, the malware generates an MD5 hash based on... number of processors... machine (hostname)... domain name... username... total number of logical drives.
The malware searches for the existence of specific driver files commonly associated with virtualization software, such as: C:\Windows\System32\drivers\VBoxMouse.sys
SHELBYLOADER utilizes sandbox detection techniques to identify virtualized or monitored environments.
SHELBYLOADER utilizes sandbox detection techniques to identify virtualized or monitored environments... WMI Query for System Information... Process Enumeration... File System Checks... Disk Size Analysis... Parent Process Verification... WMI Query for Video Controller.
It crafts HTTP requests to interact with GitHub... The request is sent to the GitHub API endpoint... https://api.github.com/repos/<owner>/<repo>/contents/<unique identifier>/<file>.
The malware executes multiple DNS queries to subdomains of arthurshelby.click. The IP addresses returned from these queries are concatenated into a byte sequence... used to generate the AES key for decrypting the backdoor.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Obfuscated .NET loader used in the current DarkBlinders campaign. It maintains registry-based persistence, reports host metadata and anti-analysis findings through GitHub, and retrieves victim-specific activation material. For selected hosts, it decrypts RuntimeBrokerApi.dll using AES-256-CBC and loads the backdoor directly into memory. It also supports GitHub credential rotation through encoded public issue comments. The report attributes the examined activity to UNC5795 with medium-to-high confidence.
ShelbyLoader is a Windows Trojan/Loader identified by unique strings, byte patterns, and API call sequences. It is designed to load additional malicious payloads onto infected systems.
A .NET loader delivered through targeted phishing attachments. It performs multiple anti-sandbox checks, establishes Run-key persistence, fingerprints and registers victims, uses GitHub or DNS-based C2 to retrieve AES key material, decrypts the backdoor payload, and loads it in memory through reflection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.