Malware Framework Gains Browser Artifact Access and Screen Control

A highly sophisticated cyberattack targeting a global manufacturing enterprise, neutralizing a stealthy new threat known as TencShell before it could hijack the corporate network.

The attempted intrusion was traced to a compromised third-party user connected to the manufacturer’s regional site in India.

According to Cato CTRL, TencShell is a customized, Go-based implant derived from the open-source Rshell command-and-control (C2) framework.

Security analysts suspect the malware has ties to Chinese threat actors, largely due to its infrastructure patterns and its clever impersonation of Tencent API services, which are designed to camouflage malicious communication.

Malware Gains Browser Access

This infection chain executes with incredible stealth. A lightweight first-stage dropper retrieves Donut shellcode disguised as a benign .woff web font file.

By hiding behind a fake font request and a spoofed user-agent, the payload easily blends into routine web traffic, bypassing standard automated security filters.

Once retrieved, the shellcode reflectively loads the customized TencShell framework directly into local memory, operating entirely without obvious cross-process memory injection.

TencShell Go paths revealing the threat actor’s REACON project (Source: catonetworks)
TencShell Go paths revealing the threat actor’s REACON project (Source: catonetworks)

Rather than acting as a simple backdoor, TencShell operates as a comprehensive operator toolkit loaded with a vast array of post-exploitation functions.

The malware can stealthily navigate the file system to browse, read, move, and extract sensitive data while enumerating active processes and logical drives.

To evade endpoint defenses, attackers can execute inline binaries, load dynamic link libraries, and run .NET assemblies directly from memory.

The framework also enables operators to establish SOCKS5 proxies, allowing them to tunnel traffic and pivot deeper into segmented internal systems.

TencShell infection chain (Source: catonetworks)
TencShell infection chain (Source: catonetworks)

Cato networks said in a report shared with Cyber Press, tencShell boasts highly invasive remote interaction features.

Operators can initiate remote screen streaming, simulate mouse and keyboard inputs, and manipulate browser artifacts by backing up or quietly wiping Chrome and Edge session data.

The framework also includes capabilities for UAC bypass and modification of the beacon sleep timer.

1st-stage dropper HTTP request with fake User-Agent (Source: catonetworks)
1st-stage dropper HTTP request with fake User-Agent (Source: catonetworks)

To ensure continuous access across system reboots, the implant establishes persistence by modifying the Windows Registry Run key.

It disguises its autorun execution under the deceptive name “OneDriveHealthTask,” allowing it to blend seamlessly alongside legitimate Microsoft background processes during casual security inspections.

Indicators of Compromise

Security teams should monitor enterprise networks for the following attacker-controlled infrastructure and IP addresses linked to the TencShell campaign:

Indicator TypeValue
IP Address45.64.52.242
IP Address192.238.134.166
IP Address45.115.38.27
Domaingin-tne-fahcesmukw[.]cn-hangzhou[.]fcapp[.]run

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories