ShellNET is a malware family tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed November 6, 2025; most recent activity November 6, 2025.
ShellNET is a newly disclosed backdoor/malware family attributed to the threat actor group 'Cavalry Werewolf' that targeted the Russian government, signaling a modern espionage operation using bespoke tooling. Its discovery underscores the ongoing use of novel backdoors in state-sponsored cyber campaigns and the persistent threat to governmental networks.
In July 2025, the Cavalry Werewolf group executed a cyberattack on a Russian government organization. The attack utilized a phishing campaign to distribute a new backdoor known as BackDoor, as well as another backdoor…