Gshell is a previously undocumented command-and-control malware framework associated with a China-linked cyber espionage campaign active in 2026. It was operated in parallel with TencShell across overlapping Hong Kong-hosted infrastructure, indicating a redundant multi-framework design intended to preserve operational uptime during intrusions. Observed activity linked to the broader campaign targeted government entities in Thailand, Afghanistan, and Taiwan, as well as financial services organizations across Europe, Australia, and Asia, with additional reconnaissance and phishing preparation against U.S. public-sector targets.
Gshell includes Linux malware variants observed on ARM and x86 systems. Reported capabilities include extraction of credentials and access tokens from enterprise messaging and cloud services, theft of login details, and file transfer functionality for upload and download. Within the wider intrusion set, operators used the infrastructure for credential harvesting, exploitation of public-facing applications, and persistence through webshell deployment, although those behaviors are not all directly attributable to the Gshell binary itself. The campaign’s tradecraft, infrastructure patterns, and targeting align with state-aligned Chinese espionage objectives, but no specific threat group has been publicly confirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously undocumented Linux malware/C2 framework used in the campaign to extract credentials and tokens from messaging and cloud services.
An undocumented secondary malware/C2 framework operated in parallel with TencShell across the same infrastructure to provide redundancy and operational uptime.
Gshell is an undocumented secondary framework operating in parallel with TencShell across the same infrastructure, apparently providing redundant command-and-control capability to improve uptime and resilience.
A separate, apparently tandem-operated command-and-control framework identified via TLS certificate metadata on overlapping infrastructure with TencShell. The report assesses with moderate confidence that it represents a second C2 used by the same operators, though no malware samples were recovered.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.