Hackers Exploit Leaked Shellter License to Distribute Lumma Stealer and SectopRAT Malware

Published:

spot_img

Hackers Exploit Shellter Tool to Distribute Malware

In a troubling trend within the cybersecurity realm, threat actors have begun leveraging Shellter, a widely used red teaming tool, to deploy stealer malware. This misuse emphasizes the ongoing challenges in safeguarding digital tools intended for ethical hacking and security testing.

The Issue at Hand

The Shellter Project recently revealed that a leak from a company that purchased Shellter Elite licenses has resulted in the weaponization of their software. This breach has allowed malicious actors to employ the tool for infostealer campaigns. To address the situation, the Shellter Project Team has issued an update designed to mitigate these vulnerabilities.

Despite their thorough vetting process, which had successfully prevented similar incidents since the launch of Shellter Pro Plus in February 2023, the team acknowledged the unfortunate circumstances of this case. Their statement reflects a deep concern for the misuse of tools intended for legitimate security practices.

Rise of Infostealer Campaigns

This situation has garnered attention, particularly following a report from Elastic Security Labs detailing how this powerful evasion framework has been misused since April 2025. Cybercriminals have been employing Shellter to distribute malware variants such as Lumma Stealer, Rhadamanthys Stealer, and SectopRAT, highlighting a new wave of financially motivated campaigns exploiting the shellcode capabilities.

The malicious efforts identified by Elastic include the packaging of payloads utilizing Shellter Elite version 11.0. The version was officially released on April 16, 2025, marking a significant escalation in the misuse of legitimate security software.

How Shellter Works

Shellter is renowned for its robustness, providing offensive security teams with the capability to bypass antivirus and endpoint detection systems. This tool’s efficacy relies on self-modifying shellcode and polymorphic obfuscation, which allows malware to embed itself into benign applications.

As noted by the Shellter Project, this sophisticated combination of legitimate code and obfuscation techniques enables malware to avoid detection from traditional security measures. In essence, it creates a façade that masks malicious intent, making it increasingly difficult for security systems to identify threats.

Tactics Used by Cybercriminals

Some of the malicious campaigns have reportedly started using this tool after its circulation on cybercrime forums. In mid-May, following the sale of Shellter version 11.0, threat actors began disseminating malware using targeted lures. These lures often attract unsuspecting users, particularly content creators interested in sponsorship opportunities or gaming modifications.

In contrast, the distribution of Lumma Stealer malware has been traced back to links hosted on MediaFire, marking a strategic approach to maximizing reach and effectiveness. By sidestepping direct downloads, cybercriminals enhance their chances of evading detection from security software.

A Broader Context of Cybersecurity Challenges

The trend of legitimate security products falling into the hands of malicious users is not new; cracked versions of tools like Cobalt Strike and Brute Ratel C4 have similarly found their way into the arsenal of cybercriminals. This history raises concerns that Shellter could follow a comparable trajectory, further intensifying the ongoing battle against cybercrime.

Moreover, the Shellter Project has expressed dissatisfaction with Elastic’s handling of the situation, accusing them of prioritizing publicity over the seriousness of public safety concerns. The project criticized Elastic for failing to notify them promptly about the exploitation, calling their actions reckless.

Conclusion

As cybersecurity continues to evolve, the repurposing of legitimate tools poses significant risks. With the rising threats from infostealer campaigns leveraging sophisticated techniques, it’s vital for both the security community and software developers to stay vigilant. Continuous monitoring and updates of security tools are crucial to combating the ever-evolving landscape of cyber threats.

spot_img

Related articles

Recent articles

Hackers used autonomous AI agent to conduct cyber-espionage on Thailand’s Ministry of Finance

Researchers from cybersecurity firm Hunt.io have reported a cyber-espionage campaign targeting Thailand's Ministry of Finance, allegedly conducted using an autonomous artificial intelligence agent. The...

Quantum Cybersecurity Careers Emerge as Top Job Opportunity for the Next Decade

Guest Post By Sudiptaa Paul Choudhury is Chief Marketing Officer at QNu Labs, a global leader in quantum cybersecurity, TEDx speaker and a LinkedIn...

CVE-2025-66376 Exploited in Russian Cyberespionage Campaign Targeting Zimbra Webmail

Unit 42 has issued an advisory regarding a persistent cyberespionage campaign identified as CL-STA-1114, which targets Zimbra webmail systems. This campaign is attributed to...

New macOS malware exploits Telegram sessions to target cryptocurrency wallets, warns SlowMist

Recent findings from blockchain security firm SlowMist reveal a new macOS malware that exploits Telegram sessions to target cryptocurrency wallets. This sophisticated information-stealing malware...