ChainShell is a previously undocumented JavaScript implant built to run under Node.js and used in operations attributed to the Iranian state-linked threat actor MuddyWater, which has been assessed as a customer of the Russian-speaking TAG-150 malware-as-a-service ecosystem. It has been observed in campaigns targeting defense, energy, government, and telecommunications organizations, with notable focus on Israeli entities as well as victims in the Middle East, the United States, and Europe.
The malware is deployed by a PowerShell-based loader that installs the Node.js runtime, decrypts and stages the implant, and launches its JavaScript components on the compromised host. ChainShell’s command-and-control design is notable for using an Ethereum smart contract to dynamically resolve its active C2 endpoint through multiple RPC providers, increasing resilience and complicating infrastructure disruption. After resolving its controller, the implant communicates over WebSocket channels protected with AES encryption.
Functionally, ChainShell is a remote implant oriented toward post-compromise operations. It can execute JavaScript code received from its server and return execution results to the operator, enabling flexible remote tasking. Reporting also describes it as supporting stealthy remote operations and command execution. The malware contains Russian-language strings and a CIS locale exclusion that avoids execution on systems in several former Soviet states, consistent with tradecraft commonly seen in Russian-speaking criminal tooling. Analysis has assessed that MuddyWater did not develop the platform itself but instead leveraged TAG-150 tooling as part of a shared multi-tenant criminal ecosystem, illustrating convergence between state espionage activity and commercial malware services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Israeli-Focused Targeting Set Targets include Israeli IP ranges, Laravel web applications, and FortiOS systems. ... MITRE ATT&CK ID Technique ... T1190 CVE-2024-55591, CVE-2024-23113, CVE-2026-1281
Israeli-Focused Targeting Set Targets include Israeli IP ranges, Laravel web applications, and FortiOS systems. ... MITRE ATT&CK ID Technique ... T1190 CVE-2024-55591, CVE-2024-23113, CVE-2026-1281
Israeli-Focused Targeting Set Targets include Israeli IP ranges, Laravel web applications, and FortiOS systems. ... MITRE ATT&CK ID Technique ... T1190 CVE-2024-55591, CVE-2024-23113, CVE-2026-1281
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers uncovered a previously undocumented Node.js-based implant, deployed via a PowerShell script (reset.ps1), enabling flexible command execution and stealthy remote operations. ChainShell uses Ethereum-based smart contracts to dynamically resolve its command-and-control (C2) infrastructure.
The key artifact found was `reset.ps1`, a PowerShell deployer for a new JavaScript-based malware we have named “ChainShell”.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Blockchain-Enabled Command and Control : ChainShell uses Ethereum-based smart contracts to dynamically resolve its command-and-control (C2) infrastructure, significantly increasing resilience against disruption.
MITRE ATT&CK ID Technique T1102.001 Ethereum smart contract dead drop resolver
Central to the operations is a PowerShell deployer ("reset.ps1") that deploys a previously undocumented JavaScript-based malware called ChainShell, which then contacts a smart contract on the Ethereum blockchain to retrieve a C2 address and use it to fetch next-stage JavaScript code for execution on compromised hosts.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware from the TAG-150 criminal ecosystem used by MuddyWater in targeted intrusions.
A newly identified Node.js-based implant/backdoor used by MuddyWater for remote command execution and stealthy operations. It uses Ethereum smart contracts for resilient C2 resolution and is deployed via a PowerShell loader.
A Node.js agent in the same threat cluster that resolves command-and-control infrastructure via an Ethereum smart contract. The content notes no shared code with DinDoor.
A JavaScript and Node.js implant used in the documented campaign; it retrieves command-and-control infrastructure from an Ethereum smart contract and uses AES-encrypted WebSocket communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.