#BlueShell
a big lead blueshell would not mattered even if gettin hit in mariokartworld
September 26, 2026 at 5:17 PM
mario must feel bad after this blueshell close to the finish line in mariokartworld
September 20, 2026 at 6:55 PM
Super Blueshell Sisters 3 sprites
September 18, 2026 at 7:43 PM
September 12, 2026 at 2:31 PM
having a big lead even with the blueshell thunder combo earlyer in mariokartworld
September 10, 2026 at 8:30 PM
i wonder if i would still gotten first without the blueshell in mariokartworld
September 8, 2026 at 7:41 PM
i was first the entire time and then blueshell happens, but i still won in mariokartworld
September 4, 2026 at 6:35 PM
i was first the entire time and then blueshell happens, but i still won in mariokartworld
September 4, 2026 at 6:34 PM
This shit ain't nothing to me! Girlfriend dropshipping that yoshi tf Zaza behind enemy lines but we got those goombas pulling us over on rainbow road going 90 in a school zone. My soul ascends and I blueshell them into 3 months from now
September 3, 2026 at 2:47 PM
Legit so excited, mainchi is probably my favorite 3dmm project out there because it's like an earnest effort. Sure stuff like rat movie or blueshell also took a lot of effort, but those are yk high effort jokes, mainchi using mixed medium with 3dmm as a base is just too cool
August 19, 2026 at 6:09 PM
a blueshell is comming and i risk it all, but i knew i would get something to protect myself against it in mariokartworld
August 13, 2026 at 5:14 PM
no blueshell for me at the end in mariokartworld
August 12, 2026 at 6:44 PM
no fancy tricks and blueshell block and get first in mariokartworld
August 11, 2026 at 7:37 PM
first win was luck that thunder happend, because the other one had a mushroom and wouls just not care for the blueshell anyways
August 10, 2026 at 12:05 AM
BlackTech APT targets Japanese organizations with a new 'BlueShell' Linux backdoor. The malware evades detection by routing C2 traffic through the victim's own internal proxy server, enabling stealthy, long-term access. #APT #BlackTech #Linux #Threat...

🌐 cyber[.]netsecops[.]io
BlackTech APT Deploys
The BlackTech APT group is using a new Linux backdoor called BlueShell to target Japanese organizations, leveraging internal proxy servers for stealthy C2...
cyber.netsecops.io
August 1, 2026 at 2:26 AM
BlackTech's Linux backdoor hides as a kernel worker and phones home through your own proxy. https://intel.threadlinqs.com/threat/TL-2026-1803 #ThreatIntel #BlueShell #PLEAD #TSCookie
July 31, 2026 at 5:55 PM
BlackTech APT Deploys BlueShell Linux Backdoor Against Japanese Organizations https://packetstorm.news/news/view/42592 #news
July 31, 2026 at 5:48 PM
To all my friends who ever hit me with a blueshell in Mario Kart... You're all race-traitors
July 31, 2026 at 2:07 PM
BlackTech APT Deploys BlueShell Linux Backdoor Against Japanese Organizations
BlackTech APT Deploys BlueShell Linux Backdoor Against Japanese Organizations
BlackTech has been linked to a newly examined Linux backdoor deployment against organizations in Japan, showing how a familiar remote-access tool can be reshaped for cyberespionage. The malware gives intruders a way to run commands, move files, and route traffic after they have already entered a network, raising the risk to internal systems and sensitive data. The attack begins after the attackers gain access and move laterally through the victim environment using SSH. From there, they deploy a loader that launches the backdoor, a method that reflects the group’s established interest in stealthy network access, including earlier  BlackTech router intrusion activity  targeting corporate networks. Analysts at IIJ Security Diary identified the malware as a Linux variant of BlueShell used during post-compromise activity by BlackTech. Data copying and XOR decoding process (Source – IIJ Security Diary) IIJ Security Diary said in a report shared with Cyber Security News (CSN) that it observed three recent variants in May 2026. BlueShell is written in Go and is based on an openly available remote-access tool, but the observed versions contain added features intended to make investigation harder. Its use against Japanese organizations also shows that BlackTech continues to adjust its tools as defenders improve monitoring. BlackTech APT Deploys BlueShell Linux Backdoor The loader decodes concealed data, decompresses the backdoor, and starts it with altered process information so it can resemble a normal Linux kernel worker. It then removes the deployed backdoor from the file system, reducing the evidence available to responders during a routine disk investigation. Execution process (Source – IIJ Security Diary) This approach makes incident response more difficult because the remaining loader may also be deleted after execution. Investigators should preserve affected systems quickly and consider file-system carving or memory forensics when expected malware files are missing, especially after suspicious SSH activity or  Linux SSH credential theft . Once active, the backdoor reads its hidden settings from environment variables and checks whether it is running on the intended host. It can then collect basic host details, receive remote commands, transfer files, open a shell, and create a SOCKS5 proxy that can help attackers reach other resources. Proxy-Based C2 Evasion A notable feature of this BlueShell variant is its ability to communicate with its command-and-control server through the victim organization’s own proxy server. Earlier versions seen before 2023 did not include this capability, while samples identified from 2024 onward have increasingly used it. Routing traffic through a trusted internal proxy can make malicious connections appear closer to normal business activity. Security teams should review unusual outbound proxy use, unexpected encrypted sessions, and new connections from Linux servers, while also examining patterns highlighted in  SOCKS5 proxy abuse campaigns . The malware also checks part of the command server’s digital certificate before continuing its connection, adding another layer of control over where it communicates. Its renamed commands appear designed to slow analysis, although researchers could still infer their purpose from information left inside the Go binary. Process checking the Common Name field (Source – IIJ Security Diary) Organizations should treat unexpected SSH movement between servers as a high-priority signal and retain endpoint, authentication, and proxy logs long enough to reconstruct attacker activity. Monitoring advice from  SSH lateral movement investigations  similarly stresses that SSH artifacts and network telemetry can reveal attacker paths even after cleanup efforts. The reported activity reinforces the need for continued vigilance around BlackTech operations targeting Japan. Fast containment, evidence preservation, and review of proxy and SSH behavior can give defenders a better chance of finding this type of intrusion before attackers expand their access. Indicators of compromise (IoCs):- Type Indicator Description SHA-256 944b774d592f5e7fe2c34ac6c3abb2a77bfa96707c4f3c33ac77b8d54800244f BlueShell variant dropper SHA-256 3228da011423853efd3d94ce3a28046b5ca19e921861ea5aee2700bc90fc1d55 BlueShell variant File name apid Name associated with the BlueShell variant dropper File name tmpkthread Name associated with the BlueShell variant C2 server 48.216.210.91:443 Reported command-and-control server address and port Proxy server 10.210.20.254:3128 Proxy server specified in the observed configuration Process disguise kworker1212 Process name used to imitate a Linux kernel worker File path tmp.ICECache Path used in a previous BlueShell deployment campaign Process disguise /usr/sbin/cron -f Process name used in a previous BlueShell deployment campaign Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Building Resilience Against Phishing & Malware and  Analyze  it in a safe environment –  Power your SOC with ANY.RUN The post BlackTech APT Deploys BlueShell Linux Backdoor Against Japanese Organizations appeared first on Cyber Security News .
cybersecuritynews.com
July 31, 2026 at 12:24 PM
BlackTech APT deploys BlueShell Linux backdoor in Japan, enhancing cyberespionage tactics and evading detection. #CyberSecurity #APT #LinuxBackdoor #BlackTech #BlueShell #Japan thedailytechfeed.com/blacktech-ap...
July 31, 2026 at 12:15 PM
BlackTech’s Hidden Linux Backdoor: How a Fake Kernel Process Helps Attackers Stay Invisible + Video

Introduction: A New Era of Stealthy Linux Intrusions Cybersecurity defenders are facing a growing challenge as advanced threat actors continue improving their ability to disappear inside…
BlackTech’s Hidden Linux Backdoor: How a Fake Kernel Process Helps Attackers Stay Invisible + Video
Introduction: A New Era of Stealthy Linux Intrusions Cybersecurity defenders are facing a growing challenge as advanced threat actors continue improving their ability to disappear inside legitimate-looking system activity. One recent example involves BlackTech, a sophisticated China-linked advanced persistent threat (APT) group that has adapted the open-source BlueShell remote access trojan (RAT) into a highly customized Linux-focused backdoor designed for stealth, persistence, and post-compromise operations.
undercodenews.com
July 31, 2026 at 10:24 AM
BlackTechが偽のLinuxカーネルプロセスにBlueShellバックドアを潜伏させる

BlackTechは、Linuxシステムに対する侵害後の活動において、カスタマイズしたBlueShellバックドアを展開していることが分かりました。攻撃者はこれを偽のカーネルワーカープロセスとして偽装し、検知を回避するとともにフォレンジック分析を困難にしています。 この亜種は、オリジナルのオープンソース版BlueSh
BlackTechが偽のLinuxカーネルプロセスにBlueShellバックドアを潜伏させる
BlackTechは、Linuxシステムに対する侵害後の活動において、カスタマイズしたBlueShellバックドアを展開していることが分かりました。攻撃者はこれを偽のカーネルワーカープロセスとして偽装し、検知を回避するとともにフォレンジック分析を困難にしています。 この亜種は、オリジナルのオープンソース版BlueSh
blackhatnews.tokyo
July 31, 2026 at 9:34 AM
BlackTech APTグループ、日本の組織を狙う攻撃で新型Linuxバックドア「BlueShell」を使用

中国と関係が深い長期活動型APTグループBlackTechが、オープンソースRAT「BlueShell」をベースにした新型Linuxバックドアを採用し、日本の組織に対する侵入後の攻撃活動に用いていることが判明しました。これはツールチェーンの継続的な進化と、企業のLinux環境への標的の絞り込みを示すものです。 Blu...
BlackTech APTグループ、日本の組織を狙う攻撃で新型Linuxバックドア「BlueShell」を使用
中国と関係が深い長期活動型APTグループBlackTechが、オープンソースRAT「BlueShell」をベースにした新型Linuxバックドアを採用し、日本の組織に対する侵入後の攻撃活動に用いていることが判明しました。これはツールチェーンの継続的な進化と、企業のLinux環境への標的の絞り込みを示すものです。 Blu
blackhatnews.tokyo
July 31, 2026 at 9:10 AM
IIJ-SECT's Bynaoki Takayam looks into three of the latest BlueShell variants observed in May 2026, primarily used in attacks by threat actors based in China. sect.iij.ad.jp/blog/2026/07...
July 30, 2026 at 9:05 AM