Skip to content

Malware

REDSHAWL

REDSHAWL is a session hijacking utility that starts a new process as another user currently logged on to the same system via command-line.

REDSHAWL is a Windows malware family operated by Lazarus Group.

Background

REDSHAWL is a command-line session-hijacking tool that spawns a new process under the identity of a different user who is currently logged into the same machine.


Source: Malpedia (Fraunhofer FKIE).