216.73.216.233

The Shelby Strategy

· Published 01/04/2025 14:48 · Modified 01/04/2025 17:58

Export JSON

Essential information

Published
01/04/2025 14:48
Modified
01/04/2025 17:58
Tags
2025-04-01 c2 github iraq obfuscation phishing sandbox-detection shelby shelbyc2 shelbyloader telecommunications uae
Related entities
1 intrusion sets (apt), 13 techniques (mitre), 2 malware, 4 others

Description

The malware family exploits for command-and-control operations, employing sophisticated techniques to evade detection. The malware consists of a loader () and a backdoor (), both obfuscated using Obfuscar. employs various sandbox detection methods and uses for initial registration and key retrieval. communicates with the attacker's infrastructure using API, allowing for file uploads, downloads, and command execution. The campaign targets Iraqi and potentially airports, utilizing highly targeted emails. Despite its sophistication, the malware's design has a critical flaw: anyone with the embedded Personal Access Token can control infected machines, exposing a significant security vulnerability.

External references