Skip to content

Malware

EntryShell

Fileless malware 'EntryShell', a variant of the KeyBoy malware, due to similarities in backdoor command IDs and debug messages with old KeyBoy samples.

EntryShell is a Windows malware family.

Background

EntryShell is fileless malware regarded as a variant of KeyBoy, an attribution based on shared backdoor command IDs and debug strings found in older KeyBoy samples. Its embedded configuration is protected using a distinctive encryption algorithm.


Source: Malpedia (Fraunhofer FKIE).