VShell is a Go-based remote access trojan and backdoor used in intrusions worldwide, particularly by Chinese-speaking threat actors and intrusion clusters associated with espionage, access brokering, and financially motivated post-compromise activity. It is a cross-platform implant with client support for Windows, Linux, and macOS, and has been observed deployed after exploitation of public-facing systems including edge appliances, mail servers, web infrastructure, containerized environments, and MS-SQL–adjacent compromises.
VShell provides full remote administration capabilities, including interactive command execution, file browsing, file upload and download, screenshot capture, proxying, port forwarding, and use of compromised hosts as SOCKS5, HTTP, or TCP/UDP relays. It supports multiple communications channels and listener types, including TCP, UDP, WebSockets, DNS, DNS-over-HTTPS, DNS-over-TLS, and object-storage-based transport. Operators have used it both as a conventional backdoor and as an in-memory payload delivered by droppers or shell scripts to reduce forensic artifacts.
The malware has been observed in campaigns involving UNC5174, Houken, UNK_MassTraction, and Larva-26009, but its use is broader than any single actor and should not be treated as uniquely attributable. It has appeared alongside tooling such as SNOWLIGHT, GOREVERSE, GotoHTTP, webshells, scanning utilities, and credential-focused post-exploitation frameworks. In some Linux intrusions, VShell was launched in memory, suppressed shell history, or masqueraded as a kernel worker process to blend into process listings. It has also been used from compromised Kubernetes and cloud-hosted Linux environments, as well as after exploitation of Roundcube vulnerabilities to establish follow-on access.
Operationally, VShell is commonly associated with exploitation of known vulnerabilities on internet-facing systems, followed by reconnaissance, internal scanning, lateral movement, persistence, and long-term access. Its ecosystem includes stagers, shellcode, stageless beacons, plugin deployment, and one-click persistence features. Publicly released earlier versions later gave way to closed-source compiled releases, and leaked builds indicate continued development. VShell is widely used as a stealthy post-exploitation access platform for espionage, foothold retention, and pivoting deeper into victim networks across government, healthcare, military, research, academic, telecommunications, finance, and other sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This one-liner functionality has commonly been used as payloads for or following remote command execution (RCE) exploits such as CVE-2025-3132418. | VShell is a full-fledged remote access trojan (RAT), programmed in Go... It has offensive capabilities such as capturing screenshots of victim computers, allows for browsing as well as uploading and downloading files, and the ability to remotely execute commands as a backdoor.
Forensic analysis identified a vulnerable Jenkins server (CVE-2024–23897) exposed on the internet as the source of the compromise. The latter served as the initial access for the threat actor...
As part of these long-running activities, we exceptionally observed adversaries trigger novel vulnerabilities such as VMware’s CVE-2025-41244 local privilege escalation. | VShell is a full-fledged remote access trojan (RAT), programmed in Go... It has offensive capabilities such as capturing screenshots of victim computers, allows for browsing as well as uploading and downloading files, and the ability to remotely execute commands as a backdoor.
NVISO observed amongst others, UNC5174’s reliance on remote code execution vulnerabilities such as CVE-2024-36401 (GeoServer33). | VShell is a full-fledged remote access trojan (RAT), programmed in Go... It has offensive capabilities such as capturing screenshots of victim computers, allows for browsing as well as uploading and downloading files, and the ability to remotely execute commands as a backdoor.
After gaining access to Roundcube servers, UNK_MassTraction exploited CVE-2025-49113, a deserialization vulnerability, to deploy a webshell or install the VShell backdoor in memory.
WP File Manager CVE-2020-25213 Remove if not needed; file-manager plugins are high-value targets.
Simple File List CVE-2025-34085 Remove unused installs and audit upload directories.
Ninja Forms CVE-2026-0740 Update and review form-related uploads and logs.
Plugin or platform CVE Action Breeze Cache CVE-2026-3844 Update immediately or disable until patched.
Custom CSS JS PHP CVE-2026-6433 Verify only trusted admins can write executable code.
ThemeREX Addons CVE-2026-1969 Patch and review new files under writable theme/plugin paths.
Joomla JCE CVE-2026-48907 Patch and inspect administrator upload paths.
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WavePlayer CVE-2025-12057
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WPBookit CVE-2025-7852
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... BerqWP CVE-2025-7443
Threat actors exploit multiple vulnerabilities, including the CVE-2024-42009 cross-site scripting flaw. Exploitation triggers automatically when a user opens the email, requiring no further interaction. | Successful attacks steal credentials, install webshells, or deploy memory-resident VShell backdoors.
The activity has similarities to a campaign disclosed by Trellix, which used a filename parsing vulnerability akin to CVE-2023-2868 to deliver VShell; however, Proofpoint cannot currently link the reported activity to UNK_MassTraction.
CVE-2025-0994 is a high-severity deserialization vulnerability in Trimble Cityworks... Successfully exploiting CVE-2025-0994 can allow authenticated attackers to conduct remote code execution (RCE) against a target’s Microsoft Internet Information Services (IIS) web server. ... the vulnerability is being exploited to deliver custom Rust-based loaders capable of loading VShell and Cobalt Strike into memory. | IoCs shared by Trimble suggest that the vulnerability is being exploited to deliver custom Rust-based loaders capable of loading VShell and Cobalt Strike into memory.
Talos has found intrusions in enterprise networks of local governing bodies in the United States (U.S.), beginning January 2025 when initial exploitation first took place. UAT-6382 successfully exploited CVE-2025-0944, conducted reconnaissance and rapidly deployed a variety of web shells and custom-made malware to maintain long-term access.
The vulnerability, tracked as CVE-2026-1731, is an operating system command injection flaw that also impacts some older versions of BeyondTrust Privileged Remote Access. The flaw allows an attacker to execute arbitrary commands on a server without the need for credentials or any user interaction. | A critical vulnerability in BeyondTrust Remote Support is facing an increase in threat activity, with hackers deploying SparkRAT and vShell backdoors and using remote management tools to conduct reconnaissance...
The attackers downloaded the Bash script from hxxp://107.173.89[.]153:60051/slt ... These functionally identical executables serve as loaders for the VShell backdoor. | The threat actors leveraged the CVE‑2025‑55182 (React2Shell) vulnerability... React2Shell is a vulnerability in the Flight protocol, which facilitates client-server communication for React Server Components. The vulnerability stems from insecure deserialization... Under certain conditions, this can enable an attacker to execute arbitrary code on the server.
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
15 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Houken operators used open-source tools previously detailed as part of UNC5174 intrusion set such as: GOREVERSE, VShell, fscan or ffuff.
VShell is a full-fledged remote access trojan (RAT), programmed in Go... It has offensive capabilities such as capturing screenshots of victim computers, allows for browsing as well as uploading and downloading files, and the ability to remotely execute commands as a backdoor.
After gaining access to Roundcube servers, UNK_MassTraction exploited CVE-2025-49113, a deserialization vulnerability, to deploy a webshell or install the VShell backdoor in memory.
the attacker installed VShell and GotoHTTP to gain control over the infected system
Talos has so far found two types of payloads deployed by TetraLoader on the infected endpoints: ... VShell stager ... The payload received by the VShell stager is in fact the actual VShell implant. VShell is a GoLang-based implant that talks to its C2 and provides a wide variety of remote access trojan-based functionalities.
The group deploys NetDraft, a .NET-based backdoor linked to the FinDraft and SquidDoor family, alongside an updated version of the CloudSorcerer backdoor and the VSHELL implant.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner.
...бэкдор VShell, который маскировал имя своего процесса под системный поток ядра.
Uses HTTP and DNS (via DNS Tunneling T1071.004 ) for its C2 communications, in addition to raw TCP/UDP.
Communication C2 : HTTPS avec URI imitant des assets statiques ( /assets/app.min.js , /assets/vendor.js , /assets/main.js )
The first piece of malicious code is a dropper embedding another vShell backdoor (v4.9.3) executed in memory, this time communicating via DNS tunneling .
Finally, as increasingly offered within the offensive space, compromised clients can be turned into proxies such as SOCKS5, HTTP or TCP/UDP. Through these proxies, attackers can tunnel additional tools within the victim environment, providing easy pivoting within victim networks and further exfiltration beyond the VShell infected client computers.
Once identified, lateral movement was achieved through remote command executions which downloaded and executed VShell from external infrastructure.
To ensure persistence after lateral movements, Houken operators notably deployed the following GOREVERSE payloads... The following public tools were observed on the victims’ network... Backdoors and other persistence mechanisms: – GOREVERSE (reverse_ssh); – ReverseSSH; – SparkRAT;
129 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
107 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote administration/backdoor tool installed to maintain control over the compromised server.
VShell is referenced as a command-and-control framework that later operated on the same server, materially connected as shared attacker infrastructure.
A Go-based backdoor supporting Windows and Linux, with TCP/HTTP/UDP C2 communications and remote command execution and file management. It can also use plugins such as Mimikatz and Fscan.
Referenced as an active command-and-control server present in the infrastructure tied to the operation, relevant to attribution and operational context rather than as the main subject malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.