216.73.216.6

SHOE RACK: A post-exploitation tool for remote shell access & TCP tunnelling through a victim device

· Published 26/06/2025 21:05 · Modified 27/06/2025 07:55

Export JSON

Essential information

Published
26/06/2025 21:05
Modified
27/06/2025 07:55
Tags
2025-06-26 dns over https firewalls fortigate post-exploitation remote shell reverse ssh shoe rack tcp tunnelling
Related entities
3 observables, 11 techniques (mitre), 1 malware

Description

is a sophisticated malware developed in Go 1.18, designed for activities. It connects to a custom SSH server at a hardcoded C2 URL, enabling remote interaction with the victim device. The malware utilizes DNS-over-HTTPS to locate its C2 server's IP address and has been observed targeting 100D series . supports various channel types, including 'session' and a non-standard 'jump' type, allowing for reverse-SSH tunneling. It also offers TCP tunneling capabilities, enabling actors to pivot into LAN networks after compromising perimeter devices. While some operational security measures are implemented, the malware's network communications are distinctive due to its impersonation of an outdated SSH version.

External references