
BlackTech Hides BlueShell Backdoor Behind a Fake Linux Kernel Process
BlackTech is deploying a customized BlueShell backdoor for post-compromise operations on Linux systems, hiding it as a fake kernel worker process to evade detection and complicate forensic analysis. This variant adds proxy-aware C2, host validation, and anti-analysis features that go beyond the original open-source BlueShell RAT. BlueShell is an open-source remote access trojan (RAT) written […]
The post BlackTech Hides BlueShell Backdoor Behind a Fake Linux Kernel Process appeared first on Cyber Security News.