TencShell and Gshell

TencShell and Gshell

THREAT INTELLIGENCE REPORT 

Prepared by   Alexander Gould, CTI Strategist, RST Cloud 

Reporting date   17 August 2026 

Collection   Scan-derived figures are as at 10 August 2026

Active infrastructure and an exposed exploitation chain

TencShell and Gshell
TencShell and Gshell

Summary 

Suspected China-linked operators are running an intrusion campaign against government bodies in Taiwan, Thailand, Afghanistan and the United States, and against billing and payment platforms across Europe, the Middle East, North America, Asia, Australasia and Latin America. Manufacturing and technology firms in Taiwan are also in scope, spanning chemicals, embedded and edge computing, and optoelectronics. RST Cloud has identified sixteen command and control servers absent from the published reporting on this campaign, and a complete Java exploitation chain exposed on the operators’ own servers. 

Cato CTRL first documented the TencShell implant in May 2026 [1]. Hunt.io published follow-up research on 14 July 2026 identifying a second command and control framework, Gshell, run by the same operators [2]. Both describe the activity as suspected China-linked; neither attaches a confidence level to that nexus and neither names a group. RST Cloud’s findings are consistent with both and do not independently raise either. 

The Gshell servers present a self-signed certificate whose subject names the framework. Self-signed certificates never reach Certificate Transparency, so they are invisible to public certificate search but are indexed by commercial scanners. Querying it returned twenty unique hosts as at 31 July 2026. Five were already named in the published reporting. The other fifteen were not, and a sixteenth appeared on 8 August 2026. 

The three servers at the centre of the published reporting are not only command and control. They are the operators’ working environment, and they expose a complete Java exploitation chain. 

What is new here 

  • Sixteen command and control servers absent from the published reporting. Twelve still presented the certificate as at 10 August 2026. 
  • A complete Java exploitation chain on the operators’ own servers, not described anywhere in the published reporting. 
  • A payload that writes a marker file before it attempts any callback, so the artefact lands even where egress was blocked. 
  • Tooling placed in the staging directory four days after the campaign was publicly reported, on file modification times. 
  • A published SSH host key fingerprint that does not reproduce. We give values that do. 
  • A domain that has survived every hosting rotation observed, xwsme.poterw[.]com. 
  • An exposed operator directory naming sixteen organisations we could resolve, thirteen of them payment institutions, plus a nationally deployed government platform we do not name. 

Twenty hosts are presently attributed to the campaign: thirteen carrying the Gshell certificate, four presenting the TencShell login panel, and the three core servers. Eleven were last recorded answering a scanned port between 3 and 9 August 2026, three weeks after the campaign was public. 

All dating rests on internet-wide scan data from two independent commercial sources plus RST Cloud’s own collection. Figures are as at 10 August 2026. 

The exploitation chain 

TencShell and Gshell - pic1
Figure 1. The staged JNDI exploitation chain, reconstructed from services exposed on the operators’ own servers. 

LDAP referral. A marshalsec referral service on 112.213.124[.]159:443. Serving LDAP on 443 rather than the default 1389 is deliberate: it survives egress filtering that permits only HTTPS. 

Class staging. A Python SimpleHTTP/0.6 directory holding Exploit.java, FastJsonTest.java, their compiled classes, a marshalsec/ directory and a binary named probe. The same listing is served from two of the three core hosts on ports 80 and 8080 of each, giving four routes to the same staged classes. 

TencShell and Gshell - pic2
Figure 2. The staging directory, one of four identical listings across the cluster, from a scanner record for 112.213.124[.]132 port 80 dated 6 August 2026. Reproduced from a response body recorded by an internet scanner, not from a request by RST. 

The payload. Exploit.java, 2,722 bytes, executes from a static initialiser, so it fires at class load. Its primary path is ProcessBuilder invoking /bin/bash -c with a /dev/tcp redirection; its fallback is a pure Java socket bridge for containerised targets with no shell. 

Critically for defenders: it writes `/tmp/jndi-verified.txt` containing `[JNDI-REVSHELL]` before attempting either path. That makes it an exploitation-validation payload rather than an implant, and it means an organisation that successfully blocked the command and control connection may still have been reached. 

Port 1099. A service on the default Java RMI registry port appeared on the staging host on 6 August 2026, absent from all earlier collection. We identify it by port number alone and read it as a possible second delivery path, not a confirmed one. 

FastJsonTest indicates Fastjson deserialisation targeting. Fastjson appears in no published reporting on this campaign. 

TencShell and Gshell - pic3
Figure 3. Campaign timeline. The amber points are tooling placed in the staging directory after the campaign was publicly reported, dated from file modification times. 

Infrastructure 

TencShell and Gshell - pic4
Figure 4. The twenty hosts presently attributed to the campaign, by framework and announcing autonomous system. 

Twelve of the sixteen still presented the certificate as at 10 August 2026. One address the published reporting already names, 192.163.167[.]6, also returned, so thirteen hosts in total carry it. 

TencShell and Gshell - pic5
Figure 5. The certificate presented by the Gshell servers, recorded on port 443 of 134.122.204[.]86. Subject and issuer are identical, which is what makes it self-signed and therefore absent from Certificate Transparency. 
Server Announcing AS (prefix) Last observed 
134.122.204[.]86 AS152194 CTG Server (134.122.204.0/24) 9 Aug 2026 
103.112.97[.]163 AS400619 AROSSCLOUD (103.112.97.0/24) 8 Aug 2026 
134.122.204[.]46 AS152194 CTG Server (134.122.204.0/24) 8 Aug 2026 
103.112.97[.]199 AS400619 AROSSCLOUD (103.112.97.0/24) 5 Aug 2026 
207.56.119[.]230 AS54801 Zillion Network (207.56.119.0/24) 5 Aug 2026 
207.56.28[.]82 AS54801 Zillion Network (207.56.28.0/24) 3 Aug 2026 
207.56.119[.]175 AS54801 Zillion Network (207.56.119.0/24) 3 Aug 2026 
207.56.28[.]60 AS54801 Zillion Network (207.56.28.0/24) 1 Aug 2026 
186.244.231[.]115 AS154376 Cloudvalley Sdn. Bhd. (186.244.231.0/24) 29 Jul 2026 
192.163.167[.]33 AS138995 Antbox Networks (192.163.167.0/24) 29 Jul 2026 
134.122.204[.]106 AS152194 CTG Server (134.122.204.0/24) 27 Jul 2026 
103.112.97[.]64 AS400619 AROSSCLOUD (103.112.97.0/24) 27 Jul 2026 

Autonomous systems are the announcing AS taken from public BGP data, not a scanner’s organisation label. Sources disagree materially on this campaign: 207.56.28[.]60 is variously labelled NTT America, NG Nebula Global and AS54801 Zillion Network, and only the last announces the /24. Country is not stated for these hosts, because it could not be established consistently. In particular, one scanner labels 186.244.231[.]115 as Brazil while three independent sources agree the /24 is announced by an APAC network. Any claim that this campaign has a South American host does not survive checking. 

Four further servers presented the certificate on 31 July 2026 and no longer do: 134.122.204[.]84, 103.112.97[.]159, 134.122.173[.]16 and 134.122.173[.]25. All four still answer on other ports, so this is a change in what they serve rather than confirmed removal. They are retained for retrospective hunting rather than current blocking. 

The domain. xwsme.poterw[.]com is presented in certificates on the panel hosts and is the only indicator observed to survive infrastructure rotation. It previously resolved to a Hong Kong host in the campaign’s own range and now resolves to 136.85.95[.]177 in Google address space, which itself presents the TencShell login panel, on a ten minute time to live. 

TencShell and Gshell - pic6
TencShell aFigure 6. The TencShell login panel as served from 136.85.95[.]177, the address the campaign domain rotated to, from a scanner record dated 22 July 2026.

The core cluster. The three servers at 112.213.124[.]132, [.]159 and [.]163 share an SSH host key, which bounds the cluster at exactly three hosts. Hunt.io’s report gives that fingerprint as 64107E3E0A333F685D1BE6386426223A030C4126AC7C295AA7B1D54C508BBACE [2]. Hashing the key material recovered from the hosts does not return that value. The key is ecdsa-sha2-nistp256; hashing the 104 byte blob directly gives SHA256:juZodZtEpBSn+8NzCRd+HaZ2Jy2mwYanov8Gy6lQGbU, hex 8ee668759b44a414a7fbc37309177e1da676272da6c186a7a2ff06cba95019b5. 

We raise that as a question rather than a correction. A host can present several host keys and a fingerprint over a different one would explain it, though only this key appears across every scanner record we hold for the three hosts. The practical consequence is the reason it is here: a defender pivoting on the published value returns no result in the two scanner sources we queried, where the values above bound the cluster immediately. 

An exposed directory on port 8888 of two core hosts serves the host’s own /tmp. It held 4,093 entries when captured on 15 July 2026, growth of 1,563 files since June, containing offensive tooling, traces of large language model tooling, and artefacts whose names indicate credential dumps, session cookies and exfiltrated data across forty-three organisation-like prefixes. Sixteen resolve to organisations we would stand behind, thirteen of them payment institutions across six regions. The largest set by a factor of six is a government administrative platform whose artefact names include its own application field names, indicating work developed against a product deployed across many public sector offices rather than one organisation’s system. It is not named here. 

A filename establishes that an operator took an interest in a target. It does not establish that the target was compromised. RST has opened none of these files. 

For defenders 

Block `xwsme.poterw[.]com` and alert on resolution. It has outlived every hosting change observed and should be the primary artefact rather than any address. 

Sweep for `/tmp/jndi-verified.txt`, or any file containing `[JNDI-REVSHELL]`, back to 1 April 2026 , including on hosts where no outbound traffic to this infrastructure was seen. Cato CTRL blocked an intrusion attempt in April 2026, before the May publication, so a window opening in May misses the earliest documented activity. 

Block the named hosts individually. Do not block 112.213.124.0/24 or 134.122.200.0/24: both are mixed-tenancy shared hosting, and 112.213.124.0/24 alone holds around sixty unrelated tenants. Take particular care with 136.85.95[.]177, which sits in cloud address space. 

Also alert on a JVM spawning /bin/bash, /bin/sh or /bin/dash, and on /dev/tcp/ command lines using the exec 0<> idiom. On Windows the equivalent is a JVM spawning cmd.exe. 

Two things not to do. Do not treat the code-audit application found on the operator hosts as an indicator; it is commodity tooling present on ninety-nine hosts globally including major cloud providers. And do not expect an alerting rule for LDAP on 443: a JVM connecting outbound on 443 is every HTTPS call a Java application makes, so that one has to be hunted against your own baseline. 

Indicators 

Gshell command and control. 134.122.204[.]46 · 134.122.204[.]86 · 134.122.204[.]106 · 103.112.97[.]64 · 103.112.97[.]163 · 103.112.97[.]199 · 192.163.167[.]33 · 207.56.28[.]60 · 207.56.28[.]82 · 207.56.119[.]175 · 207.56.119[.]230 · 186.244.231[.]115 

Retained for retrospective hunting, not current blocking. 134.122.204[.]84 · 103.112.97[.]159 · 134.122.173[.]16 · 134.122.173[.]25 

TencShell command and control. 112.213.124[.]132 · 112.213.124[.]159 · 112.213.124[.]163 · 134.122.200[.]153 · 134.122.200[.]155 · 134.122.200[.]197 · 136.85.95[.]177 

Domain. xwsme.poterw[.]com, currently resolving to 136.85.95[.]177 

Out of band callback. edin1s.dnslog[.]cn, observed in the Fastjson test harness. A commodity interaction service; treat as a hunting lead rather than a block. 

Host artefact. /tmp/jndi-verified.txt, containing [JNDI-REVSHELL] 

File. Exploit.java, 2,722 bytes. No hash is published: the file was transcribed rather than retained, and a hash computed over a transcription is not a hash of the file. 

Limitations

  • Observation dates are scan dates. A port answering does not establish that a command and control service was operational, or that any victim was connected. 
  • File modification times are attacker-controlled. The dates on which tooling was placed rest on metadata the operators can set to any value. 
  • Organisation names inferred from filenames are inferences. They establish operator interest, not compromise, and several rest on short tokens that may resolve differently. 
  • The payload’s behaviour rests on a single retrieval we cannot repeat. Exploit.java was read once, on 31 July 2026, through a third-party HTTP client, and was not retained. That covers the /tmp/jndi-verified.txt claim underpinning the hunting recommendation above. We are confident in it and cannot independently verify it. 
  • The RMI service on port 1099 is identified by port number alone, uncorroborated from a second source. 

RST Cloud made no connection to this infrastructure from its own network. Two source files were retrieved on 31 July 2026 through a third-party online HTTP client, so those requests originated from that service. 

Disclosure 

The relevant national CERTs were notified on 10 August 2026, following notification on 31 July 2026 of the vendors whose reporting this work extends. Release was held at a recipient’s request while it undertook enquiries. 

References 

  • Cato CTRL, 13 May 2026. “Cato CTRL Threat Research: Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware”. https://www.catonetworks.com/blog/cato-ctrl-suspected-china-linked-threat-actor-targets-global-manufacturer/ 
  • Hunt.io, 14 July 2026. “Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries”. https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion 

By Alexander Gould, RST Cloud CTI Strategist 

Contact us for a demo.