Description

The Shell Access or Remote Shell feature in malware provides attackers with a remote interface to the compromised system, essentially acting as a backdoor that allows them to execute commands as if they were physically present at the machine. This level of access gives attackers a near-omnipotent control over the target, allowing them to perform a wide range of actions from file manipulation to launching additional exploits. One of the most significant capabilities offered by shell access is the potential for privilege escalation. By exploiting vulnerabilities or misconfigurations in the system, an attacker can elevate their access rights, gaining more thorough control and making it easier to carry out further malicious activities. Moreover, a remote shell can be used to pivot to other systems on the network, enabling lateral movement and increasing the scope of the attack.


Categories Lateral Movements, Privilege Escalation, System Management
Dangerousness High

Existing Technique

Name Associated Feature(s) Has Snippet Matching Sample
Execute Programs logoExecute Programs File Manager, Shell Access 0

Associated with Releases

Version Origins Authors Languages Release Date
NetBus 1.70 logoNetBus 1.70 Sweden 🇸🇪 cf Delphi Nov, 1998
Coma 1.0.9 logoComa 1.0.9 Unknown 🏴‍☠️ ThePr0 , UserUnFriendly , GoatAss , JohnFive Visual Basic 6 (VB6) Mar, 1999
SubSeven 2.0 logoSubSeven 2.0 Romania 🇷🇴, Canada 🇨🇦 Mobman Delphi Sep, 1999
SchoolBus 2.0 logoSchoolBus 2.0 Turkey 🇹🇷 Serdar Kabaoglu Delphi Oct, 1999
SubSeven 2.1 logoSubSeven 2.1 Romania 🇷🇴, Canada 🇨🇦 Mobman Delphi Nov, 1999
SubSeven 2.1.1 GOLD edition logoSubSeven 2.1.1 GOLD edition Romania 🇷🇴, Canada 🇨🇦 Mobman Delphi Feb, 2000
SubSeven 2.1.2 M.U.I.E logoSubSeven 2.1.2 M.U.I.E Romania 🇷🇴, Canada 🇨🇦 Mobman Delphi Apr, 2000
SubSeven 2.1.3 BONUS logoSubSeven 2.1.3 BONUS Romania 🇷🇴, Canada 🇨🇦 Mobman Delphi Jun, 2000
SubSeven 2.1.4 DEFCON 8 logoSubSeven 2.1.4 DEFCON 8 Romania 🇷🇴, Canada 🇨🇦 Mobman Delphi Jul, 2000
Y3K rat 1.5 logoY3K rat 1.5 Greece 🇬🇷 firelarm , Chucky Delphi Jan, 2001
SubSeven 2.2 logoSubSeven 2.2 Romania 🇷🇴, Canada 🇨🇦 Mobman Delphi Mar, 2001
Y3K rat 1.6 logoY3K rat 1.6 Greece 🇬🇷 firelarm , Chucky Delphi May, 2001
Y3K rat 1.6 MS logoY3K rat 1.6 MS Greece 🇬🇷 firelarm , Chucky Delphi Jul, 2001
Net-Devil 1.5 logoNet-Devil 1.5 Unknown 🏴‍☠️ Nilez Delphi Jul, 2002
MoSucker 3.0b logoMoSucker 3.0b Germany 🇩🇪 Superchachi Visual Basic 6 (VB6) Nov, 2002
SubSeven 2.1.5 Legends logoSubSeven 2.1.5 Legends Romania 🇷🇴, Canada 🇨🇦 Mobman Delphi Feb, 2003
CIA 1.0 logoCIA 1.0 England 🏴󠁧󠁢󠁥󠁮󠁧󠁿 Alchemist Visual Basic 6 (VB6) Mar, 2003
Z-dem0n 1.26 logoZ-dem0n 1.26 Unknown 🏴‍☠️ ZnAsH Delphi Mar, 2003
CIA 1.1 logoCIA 1.1 England 🏴󠁧󠁢󠁥󠁮󠁧󠁿 Alchemist Visual Basic 6 (VB6) Apr, 2003
Optix Pro 1.32 logoOptix Pro 1.32 Unknown 🏴‍☠️ s13az3 , xMs Delphi Sep, 2003
CIA 1.2 logoCIA 1.2 England 🏴󠁧󠁢󠁥󠁮󠁧󠁿 Alchemist Visual Basic 6 (VB6) Sep, 2003
Beast 2.05 logoBeast 2.05 Romania 🇷🇴 Tataye Delphi Sep, 2003
Beast 2.02 logoBeast 2.02 Romania 🇷🇴 Tataye Delphi Sep, 2003
Fearless Lite 1.01 logoFearless Lite 1.01 Australia 🇦🇺, France 🇫🇷 Read101 , Triforce Delphi Nov, 2003
ProRat 1.2 logoProRat 1.2 Turkey 🇹🇷 HighLander , ATmaCA Borland C++ Jan, 2004
ProRat 1.3 logoProRat 1.3 Turkey 🇹🇷 HighLander , ATmaCA Borland C++ Feb, 2004
Nuclear RAT 1.0 Beta 5 logoNuclear RAT 1.0 Beta 5 Brazil 🇧🇷 caesar2k Delphi Feb, 2004
Beast 2.06 logoBeast 2.06 Romania 🇷🇴 Tataye Delphi Feb, 2004
ProRat 1.4 logoProRat 1.4 Turkey 🇹🇷 HighLander , ATmaCA Borland C++ Feb, 2004
ProRat 1.6 logoProRat 1.6 Turkey 🇹🇷 HighLander , ATmaCA Borland C++ Mar, 2004
ProRat 1.8 logoProRat 1.8 Turkey 🇹🇷 HighLander , ATmaCA Borland C++ Mar, 2004
Infector NG 2004 2.1.0 logoInfector NG 2004 2.1.0 Belgium 🇧🇪, United Kingdom 🇬🇧 fc , Infiltration Delphi May, 2004
Optix Pro 1.33 logoOptix Pro 1.33 Unknown 🏴‍☠️ s13az3 Delphi Aug, 2004
Beast 2.07 logoBeast 2.07 Romania 🇷🇴 Tataye Delphi Aug, 2004
Institution 2004 0.4.0 logoInstitution 2004 0.4.0 United States 🇺🇸 Aphex Delphi Oct, 2004
CIA 1.3 logoCIA 1.3 England 🏴󠁧󠁢󠁥󠁮󠁧󠁿 Alchemist Visual Basic 6 (VB6) Dec, 2004
Messiah 4.0 logoMessiah 4.0 Unknown 🏴‍☠️ Splinter Visual Basic 6 (VB6) Jan, 2005
ProRat 1.9 logoProRat 1.9 Turkey 🇹🇷 HighLander , ATmaCA Borland C++ Mar, 2005
TrojNa$ 1.0 logoTrojNa$ 1.0 Unknown 🏴‍☠️, Australia 🇦🇺 flippmode , Satan_Addict , Read101 Delphi Jan, 2006
Bersek 1.1 logoBersek 1.1 Brazil 🇧🇷 XpyXt Visual Basic 6 (VB6) Jun, 2006
Bifrost 1.2.1 logoBifrost 1.2.1 Sweden 🇸🇪 ksv C++ Jan, 2007
Hav-Rat 1.2 logoHav-Rat 1.2 Sweden 🇸🇪 Havalito Delphi Feb, 2007
Bandook 1.35 logoBandook 1.35 Lebanon 🇱🇧 PrinceAli Delphi, C++ Apr, 2007
Poison Ivy 2.3.0 logoPoison Ivy 2.3.0 Sweden 🇸🇪 Shapeless Delphi, MASM Jun, 2007
Hav-Rat 1.3.2 logoHav-Rat 1.3.2 Sweden 🇸🇪 Havalito Delphi Jul, 2007
sharK 2.4.0 Fwb+ logosharK 2.4.0 Fwb+ Germany 🇩🇪 sNiper109 , rockZ Visual Basic 6 (VB6) Aug, 2007
DARKMOON 4.11 Private Edition logoDARKMOON 4.11 Private Edition Spain 🇪🇸 shukisnike Delphi Aug, 2007
Nuclear RAT 2.1.0 logoNuclear RAT 2.1.0 Brazil 🇧🇷 caesar2k Delphi Sep, 2007
Poison Ivy 2.3.2 logoPoison Ivy 2.3.2 Sweden 🇸🇪 Shapeless Delphi, MASM Jan, 2008
Lost Door 1.0 logoLost Door 1.0 Tunisia 🇹🇳 OussamiO Visual Basic 6 (VB6) Jan, 2008