ShellHub
ShellHub (cloud.shellhub.io / shellhub.io) is an open-source SSH gateway that enrolls devices via a per-tenant install script and gives operators browser-based remote terminal access through the ShellHub web dashboard. The agent installs via `curl -sSf "https://cloud.shellhub.io/install.sh?tenant_id=<TENANT_ID>" | sh` and registers the host into the operator's tenant; subsequent SSH connections are brokered through the ShellHub cloud over the persistent agent connection, with no inbound firewall change required on the device. Catalogued by the LOTTunnels project under the "shell access" category; documentation explicitly notes potential misuse by "insiders as well as threat actors" for "a variety of malicious tasks". Both a hosted SaaS (cloud.shellhub.io) and a self-hostable Docker deployment exist.
Tool overview
- Category
- RAT
- Research authors
- @MHaggis
- Created
- 2026-05-18
- Last modified
- 2026-09-22
- Privileges
- root (installer uses curl|sh as root)
- Free / availability
- Yes (open-source + free hosted tier + paid subscription)
- Verification required
- Tenant signup required; per-tenant install token (`tenant_id`) embedded in install URL
- Supported platforms
Linux
macOS
Capabilities
Executables & installation paths
- Filename
- shellhub-agent
- OriginalFileName
- shellhub-agent
- Description
- ShellHub agent binary (Go). Maintains the persistent reverse connection to the ShellHub gateway and brokers inbound SSH sessions.
Installation paths
FORENSIC EVIDENCE
Disk artifacts
- File
- /usr/local/bin/shellhub-agent
- Description
- ShellHub agent binary (default install path used by the vendor install.sh)
- OS
- Linux
- File
- /etc/shellhub-agent/agent.env
- Description
- ShellHub agent environment file (tenant_id, server_address, identity)
- OS
- Linux
- File
- /etc/systemd/system/shellhub-agent.service
- Description
- systemd unit file for ShellHub agent persistence
- OS
- Linux
FORENSIC EVIDENCE
Network artifacts
- Description
- Hosted ShellHub control plane. Self-hosted Docker deployments may use an operator-controlled domain instead.
- Domains
- shellhub.io
- cloud.shellhub.io
- www.shellhub.io
- *.shellhub.io
- Ports
- 443
- 80
FORENSIC EVIDENCE
Other artifacts
- Type
- Other
- Value
- Install command: curl -sSf "https://cloud.shellhub.io/install.sh?tenant_id=<TENANT_ID>" | sh (high-signal hunt pattern — curl-to-sh from cloud.shellhub.io with tenant_id parameter)
- Type
- Other
- Value
- LOTTunnels project — Shell Access category: https://lottunnels.github.io/lottunnels/Binaries/shellhub/
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/shellhub_network_sigma.yml
- Description
- Detects potential network activity of ShellHub RMM tool
References
Acknowledgements
- Person
- rcKillam
- Handle
- @rcKillam
- Person
- Michael Haag
- Handle
- @MHaggis