TencShell is a Go-based implant and post-compromise remote access framework derived from the open-source Rshell project. It has been observed in 2026 intrusion activity assessed as likely China-linked, including an attempted compromise of a global manufacturing enterprise and broader espionage-oriented operations tied to related command-and-control infrastructure. Its communications were customized to resemble Tencent-themed API traffic, and associated infrastructure has been linked to parallel operational tooling and victim data collection environments.
TencShell is designed to provide attackers with broad remote control over compromised systems. Documented capabilities include remote command execution, in-memory payload execution, file transfer, interactive screen capture and streaming, keyboard and mouse simulation, process and system profiling, SOCKS5 proxying, multiplexed tunneling, DLL loading, and deployment of additional tooling. Analysis also indicates support for browser artifact access, including theft of saved sessions, cookies, login data, enterprise messaging credentials, and cloud service access material, creating opportunities for both credential theft and session hijacking. The malware also includes a UAC bypass capability and persistence mechanisms on Windows.
Observed delivery involved a multi-stage infection chain. A lightweight first-stage dropper retrieved a disguised payload container holding Donut shellcode, which then reflectively loaded the TencShell implant directly into memory. This execution flow emphasized stealth and reduced on-disk exposure. Separate reporting tied TencShell infrastructure to active intrusion campaigns involving credential harvesting, phishing-page staging, exploitation of public-facing applications, and exfiltration of victim data across manufacturing, supply chain, government, public sector, and financial services targets in multiple regions.
TencShell has been associated with Windows-focused tradecraft and also with Linux variants recovered from related infrastructure, including ARM and x86 builds. The malware and its surrounding infrastructure indicate a modular, actively maintained capability intended for espionage, remote administration of compromised hosts, and follow-on post-exploitation operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack was intercepted at the company’s India site and traced back to a third-party user with a legitimate connection to the customer’s internal environment. Attackers exploited that trusted access as a bridge, effectively turning a routine business relationship into a dangerous and highly capable entry point.
0x0B EXECUTE_COMMAND Execute system command... 0x17 INTERACTIVE_SHELL Launch shell session
If successful, TencShell could have given the attacker remote command execution, in-memory payload execution, proxying, pivoting, system profiling, and a path to deploy additional tooling.
During execution, TencShell invokes Windows Registry APIs through Go runtime wrappers to access and modify registry values.
After retrieval, the shellcode was loaded into a memory region, marked as executable, and launched through a new thread within the originating process.
Their investigation revealed a carefully constructed attack chain involving staged payloads, masqueraded file types, and command-and-control communication specifically designed to blend into normal web traffic.
The dropper then retrieved what appeared to be a standard web font file with a .woff extension, the kind websites routinely use to load custom typefaces. Inside that file was Donut shellcode
The next stage involved retrieving Donut shellcode through a masqueraded .woff resource... By placing malicious content behind a font-looking path or extension, the attacker makes the payload request appear like a routine static web asset.
Functions like SendInput, MouseClick, KeyTap, and GetScreenWebSocket were all embedded within the tool, giving an operator direct interactive control of an infected host.
The operation uncovered by Hunt researchers pivoted off known TencShell command-and-control (C2) infrastructure originally documented by Cato CTRL in May 2026.
TencShell used web-like communication patterns designed to make malicious traffic harder to distinguish from normal application traffic.
AZUREVEIL supports 36 commands that allow it to perform a wide range of post-compromise actions on the host, including ... port forwarding, SOCKS proxy control...
pkg/services/proxy/socks5.go Proxy traffic through the compromised host... pkg/services/proxy/mux/ Multiplex traffic for tunneling or pivoting
Combined with SOCKS5 proxying, DLL loading, file transfer, and persistence through a registry run key disguised as “OneDriveHealthTask,” TencShell is built for long-term, stealthy access
Some of the observed C2 paths used Tencent-like naming... This type of naming can help attacker-controlled traffic blend into normal web/API activity.
83 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named only as known command-and-control infrastructure in a separate China-linked intrusion discussion involving AI-assisted operations.
A named malware/C2 framework used in the China-linked espionage campaign as core command-and-control infrastructure supporting intrusion operations and stolen data staging.
TencShell is described as a command-and-control framework used in a China-linked cyber espionage campaign. It supported operational infrastructure tied to victim source code, custom exploit scripts, operator logs, phishing assets, and broader intrusion activity.
Go-based implant derived from the open-source Rshell framework and used as command-and-control malware in an active intrusion campaign. The content ties it to a broader operation targeting government and financial-sector entities and to infrastructure used for malware delivery and C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.