Tiny SHell is a lightweight backdoor originally released as an open-source remote shell utility and later adapted into multiple malicious variants for Linux, UNIX, and macOS. It has been used in targeted intrusion activity, including APT operations against Mac users, and has also served as the code base for related malware such as Rekoobe. Core functionality associated with Tiny SHell includes remote command execution through shell access and basic backdoor communications, with some derivative variants also supporting file transfer. Linux and UNIX-targeting variants have been observed across multiple architectures, including SPARC, while macOS variants have appeared as customized implants with added stealth and operational controls.
Malicious Tiny SHell derivatives have incorporated anti-analysis and evasion features such as string obfuscation, externalized configuration, code signing, anti-debugging checks, and process masquerading. A documented macOS variant used XOR-obfuscated strings, an INI-style configuration file, and debugger-detection logic, while retaining the underlying Tiny SHell backdoor behavior. Tiny SHell has also appeared in broader Linux intrusion chains, including TeamTNT activity, where it was downloaded alongside cryptominers, IRC bot malware, and tunneling tools during post-compromise operations and propagation workflows. Delivery observed for malicious Tiny SHell use includes installation over SSH with compromised credentials. Overall, Tiny SHell is best understood as a compact backdoor framework whose open-source availability has enabled reuse, modification, and incorporation into both commodity and state-linked intrusion sets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In addition to spreading to other machines the following files are downloaded: docker-update (XMRig) tshd (Tiny SHell) kube (Tsunami) bioset (Rathole).
3 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux/UNIX backdoor; content describes YARA detections for ELF variants (including SPARC) using byte patterns, XOR sequences, and syscall-name artifacts.
A small Unix backdoor mentioned as one of the tools downloaded by TeamTNT during lateral movement and post-compromise activity.
Open-source backdoor program whose source code served as the basis for Rekoobe. It supports encrypted C2 communications and both reverse-shell and bind-shell style operation.
A lightweight macOS backdoor based on the open-source Tiny SHell project. The modified variant discussed ('TinyTim') adds XOR-encoded strings, an external INI-style config file, embedded password obfuscation, and anti-debugging checks, then connects to a command-and-control server to provide remote shell access similar to SSH.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.