ShelbyLoader / ShelbyC2
malware · malware:shelbyloader single-source
C# loader and RAT pair that takes tasking through the GitHub API and issue comments; documented by Elastic as part of The Shelby Strategy and as version 2 by Unit 42 in the Blinder Tunnel campaign (Unit 42, 2026-10-06).
Aliases: ShelbyLoader V2, ShelbyC2 V2, SHELBYLOADER, SHELBYC2
Defender insights
What each entry about ShelbyLoader / ShelbyC2 tells a defender to do, newest first.
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
used by
- CL-STA-1178Unit 42: the attackers deployed ShelbyLoader V2 and ShelbyC2 V2
Story timeline
Hunting pivots
ATT&CK techniques (12 across 6 tactics)
12 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionCommand and Scripting Interpreter: PowerShell · Trusted Developer Utilities Proxy Execution: MSBuild · User Execution: Malicious File · Hijack Execution Flow: DLL · Hijack Execution Flow: AppDomainManager
- PersistenceBoot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- Privilege EscalationBoot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- StealthObfuscated Files or Information · Masquerading: Match Legitimate Resource Name or Location · Trusted Developer Utilities Proxy Execution: MSBuild · Hijack Execution Flow: DLL · Hijack Execution Flow: AppDomainManager
- Defense ImpairmentDisable or Modify Tools
- Command and ControlWeb Service: Dead Drop Resolver · Web Service: Bidirectional Communication · Protocol Tunneling
Execution TA0002
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
T1127.001Trusted Developer Utilities Proxy Execution: MSBuild×1
Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
T1574.014Hijack Execution Flow: AppDomainManager×1
Adversaries may execute their own malicious payloads by hijacking how the .NET `AppDomainManager` loads assemblies. The .NET framework uses the `AppDomainManager` class to create and manage one or more isolated runtime environments (called application domains) inside a process to host the execution of .NET applications. Assemblies (`.exe` or `.dll` binaries compiled to run as .NET code) may be loaded into an application domain as executable code.
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
Persistence TA0003
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
Privilege Escalation TA0004
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
T1127.001Trusted Developer Utilities Proxy Execution: MSBuild×1
Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
T1574.014Hijack Execution Flow: AppDomainManager×1
Adversaries may execute their own malicious payloads by hijacking how the .NET `AppDomainManager` loads assemblies. The .NET framework uses the `AppDomainManager` class to create and manage one or more isolated runtime environments (called application domains) inside a process to host the execution of .NET applications. Assemblies (`.exe` or `.dll` binaries compiled to run as .NET code) may be loaded into an application domain as executable code.
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
Defense Impairment TA0112
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
Command and Control TA0011
T1102.001Web Service: Dead Drop Resolver×1
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
T1102.002Web Service: Bidirectional Communication×1
Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet.
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
T1572Protocol Tunneling×1
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.
Evidence: 2026-10-07/cl-sta-1178-blinder-tunnel-csproj-lure-github-c2 · ATT&CK page ↗
Entries about ShelbyLoader / ShelbyC2 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Blackwood×1
- Blinder Tunnel×1
- CL-STA-1178×1
- Microsoft .NET Framework×1
- Microsoft Visual Studio×1
- Screening Serpens×1
Where this entity is cited
Source distribution
- unit42.paloaltonetworks.com1 (100%)