Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A renamed, legitimate Visual Studio hosting process loaded RuntimeBroker.dll, the ShelbyLoader V2 loader.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader delivered through a weaponized Visual Studio project and DLL sideloading. It establishes registry Run-key persistence, profiles the host, uploads a machine fingerprint and retrieves commands through GitHub's API. It supports a fallback using encrypted data in GitHub issue comments, decrypts ShelbyC2 V2 and stages Blackwood.
C# loader deployed through a weaponized Visual Studio project, AppDomainManager hijacking and DLL sideloading. It fingerprints hosts, performs anti-analysis checks, establishes registry persistence and communicates through GitHub repositories. An encrypted GitHub Issues fallback mechanism can update its C2 configuration when authentication fails. It decrypts and loads the ShelbyC2 V2 payload into memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.