RAT

ShellHub

ShellHub (cloud.shellhub.io / shellhub.io) is an open-source SSH gateway that enrolls devices via a per-tenant install script and gives operators browser-based remote terminal access through the ShellHub web dashboard. The agent installs via `curl -sSf "https://cloud.shellhub.io/install.sh?tenant_id=<TENANT_ID>" | sh` and registers the host into the operator's tenant; subsequent SSH connections are brokered through the ShellHub cloud over the persistent agent connection, with no inbound firewall change required on the device. Catalogued by the LOTTunnels project under the "shell access" category; documentation explicitly notes potential misuse by "insiders as well as threat actors" for "a variety of malicious tasks". Both a hosted SaaS (cloud.shellhub.io) and a self-hostable Docker deployment exist.

Tool overview

Category
RAT
Research authors
@MHaggis
Created
2026-05-18
Last modified
2026-09-22
Privileges
root (installer uses curl|sh as root)
Free / availability
Yes (open-source + free hosted tier + paid subscription)
Verification required
Tenant signup required; per-tenant install token (`tenant_id`) embedded in install URL
Supported platforms
LinuxmacOS

Capabilities

Browser-based remote SSH (interactive terminal via web dashboard)Cloud-relayed SSH (no inbound firewall change required on agent host)SSH key + username/password authenticationDevice enrollment / tenant registrationDocker container deployment of the gateway (self-hosted option)

Executables & installation paths

Filename
shellhub-agent
OriginalFileName
shellhub-agent
Description
ShellHub agent binary (Go). Maintains the persistent reverse connection to the ShellHub gateway and brokers inbound SSH sessions.

Installation paths

/usr/local/bin/shellhub-agent
/etc/shellhub-agent/*
/etc/systemd/system/shellhub-agent.service
/var/lib/shellhub-agent/*

FORENSIC EVIDENCE

Disk artifacts

File
/usr/local/bin/shellhub-agent
Description
ShellHub agent binary (default install path used by the vendor install.sh)
OS
Linux
File
/etc/shellhub-agent/agent.env
Description
ShellHub agent environment file (tenant_id, server_address, identity)
OS
Linux
File
/etc/systemd/system/shellhub-agent.service
Description
systemd unit file for ShellHub agent persistence
OS
Linux

FORENSIC EVIDENCE

Network artifacts

Description
Hosted ShellHub control plane. Self-hosted Docker deployments may use an operator-controlled domain instead.
Domains
  • shellhub.io
  • cloud.shellhub.io
  • www.shellhub.io
  • *.shellhub.io
Ports
  • 443
  • 80

FORENSIC EVIDENCE

Other artifacts

Type
Other
Value
Install command: curl -sSf "https://cloud.shellhub.io/install.sh?tenant_id=<TENANT_ID>" | sh (high-signal hunt pattern — curl-to-sh from cloud.shellhub.io with tenant_id parameter)
Type
Other
Value
LOTTunnels project — Shell Access category: https://lottunnels.github.io/lottunnels/Binaries/shellhub/

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/shellhub_network_sigma.yml
Description
Detects potential network activity of ShellHub RMM tool

References

Acknowledgements

Person
rcKillam
Handle
@rcKillam
Person
Michael Haag
Handle
@MHaggis