Shellapp VNC RAT (provisional)

Malware family · 1 sample(s) · 4 indicator record(s) · 1 signing certificate(s)

About Shellapp VNC RAT (provisional)

VNC-over-WebSocket remote-access payload shipped behind the “shellapp” native dropper (same packer as Telegram Phish Proxy). The unpacked stealer carries a plaintext assets/c2_config.json with a panel API URL and a vnc_server_url plus fallbacks, and an assets/mode.json marking device_type: rat. Distinct from the Telegram Phish Proxy payload (which uses a ws://<ip>:9800 device relay and a phishing WebView); here the operator drives a VNC session over wss://. C2 indicators are recovered by a full static unpack of the dropper. Family label provisional.

Indicators

IndicatorTypeSampleFirst seen
appmetric-cdn.buzz/vnc-ws domain 844b58576a5f… 2026-09-29
cloudmetric-api.top/vnc-ws domain 844b58576a5f… 2026-09-29
netpulseapichill.biz/vnc-ws domain 844b58576a5f… 2026-09-29
testdomain-lil.shop/vnc-ws domain 844b58576a5f… 2026-09-29