Shellapp VNC RAT (provisional)
Malware family · 1 sample(s) · 4 indicator record(s) · 1 signing certificate(s)
About Shellapp VNC RAT (provisional)
VNC-over-WebSocket remote-access payload shipped behind the “shellapp” native dropper (same packer as Telegram Phish Proxy). The unpacked stealer carries a plaintext
assets/c2_config.json with a panel API URL and a vnc_server_url plus fallbacks, and an assets/mode.json marking device_type: rat. Distinct from the Telegram Phish Proxy payload (which uses a ws://<ip>:9800 device relay and a phishing WebView); here the operator drives a VNC session over wss://. C2 indicators are recovered by a full static unpack of the dropper. Family label provisional.Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| appmetric-cdn.buzz/vnc-ws | domain | 844b58576a5f… | 2026-09-29 |
| cloudmetric-api.top/vnc-ws | domain | 844b58576a5f… | 2026-09-29 |
| netpulseapichill.biz/vnc-ws | domain | 844b58576a5f… | 2026-09-29 |
| testdomain-lil.shop/vnc-ws | domain | 844b58576a5f… | 2026-09-29 |