VShell is a Go-based remote-access trojan and post-exploitation toolkit supporting Windows, Linux, and macOS. It provides interactive command execution, screenshot capture, file browsing, uploads and downloads, network discovery, port forwarding, and proxying. Its modular architecture supports plugin deployment, including credential-access and network-scanning tools such as Mimikatz and fscan, and includes built-in persistence features. Compromised hosts can function as SOCKS5, HTTP, or TCP/UDP proxies to support pivoting and data exfiltration.
VShell supports stagers, shellcode, and full beacons, with command-and-control options including TCP, UDP, WebSocket, DNS, DNS-over-HTTPS, DNS-over-TLS, and object-storage services. Its network traffic uses AES-GCM encryption. Observed deployments include memory-resident payloads delivered by SNOWLIGHT and other loaders. Stealth features include anti-sandbox checks, suppression of operator-command logging, and shell-history suppression. Earlier versions were publicly released before development shifted to closed-source and restricted distribution.
VShell is commonly deployed after exploitation of vulnerable public-facing applications and appliances. Documented infection chains include exploitation of Roundcube, GeoServer, Cityworks, and AI research infrastructure, as well as spearphishing attachments using fake academic résumés. It has affected government, healthcare, military, university, and research organizations, including researchers working on applied AI and energy systems.
VShell has been used by multiple intrusion clusters, including UNC5174, Earth Lamia, UNK_MassTraction, and Larva-26009. Its use spans espionage, pre-positioning, access brokering, and financially motivated intrusions. Although frequently associated with Chinese-speaking and China-nexus operators, VShell is shared across distinct activity clusters, and its presence alone does not establish attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
AWS reported within hours of public disclosure, multiple China state-nexus threat groups, including Earth Lamia and Jackpot Panda, had been exploiting CVE-2025-55182 for initial access.
The attackers have been leveraging a Cityworks RCE vulnerability (CVE-2025-0994) to get access to the targeted environments and perform the initial reconnaissance.
CVE-2023-48022 was used to hack into domestic AI-related research servers back in April, bouncing the shell and then executing bash scripts and plugins with the same origin as above, eventually loading Vshell.
“More recently, Earth Lamia also exploited CVE-2025-31324 (SAP NetWeaver Visual Composer unauthenticated file upload vulnerability).” The attribution discussion connects exploitation campaigns to Cobalt Strike infrastructure and a VShell deployment involving the SNOWLIGHT stager.
Forensic analysis identified a vulnerable Jenkins server (CVE-2024–23897) exposed on the internet as the source of the compromise. The latter served as the initial access for the threat actor...
As part of these long-running activities, we exceptionally observed adversaries trigger novel vulnerabilities such as VMware’s CVE-2025-41244 local privilege escalation. | VShell is a full-fledged remote access trojan (RAT), programmed in Go... It has offensive capabilities such as capturing screenshots of victim computers, allows for browsing as well as uploading and downloading files, and the ability to remotely execute commands as a backdoor.
NVISO observed amongst others, UNC5174’s reliance on remote code execution vulnerabilities such as CVE-2024-36401 (GeoServer33). | VShell is a full-fledged remote access trojan (RAT), programmed in Go... It has offensive capabilities such as capturing screenshots of victim computers, allows for browsing as well as uploading and downloading files, and the ability to remotely execute commands as a backdoor.
After gaining access to Roundcube servers, UNK_MassTraction exploited CVE-2025-49113, a deserialization vulnerability, to deploy a webshell or install the VShell backdoor in memory.
WP File Manager CVE-2020-25213 Remove if not needed; file-manager plugins are high-value targets.
Simple File List CVE-2025-34085 Remove unused installs and audit upload directories.
Ninja Forms CVE-2026-0740 Update and review form-related uploads and logs.
Plugin or platform CVE Action Breeze Cache CVE-2026-3844 Update immediately or disable until patched.
Custom CSS JS PHP CVE-2026-6433 Verify only trusted admins can write executable code.
ThemeREX Addons CVE-2026-1969 Patch and review new files under writable theme/plugin paths.
Joomla JCE CVE-2026-48907 Patch and inspect administrator upload paths.
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WavePlayer CVE-2025-12057
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WPBookit CVE-2025-7852
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... BerqWP CVE-2025-7443
Threat actors exploit multiple vulnerabilities, including the CVE-2024-42009 cross-site scripting flaw. Exploitation triggers automatically when a user opens the email, requiring no further interaction. | Successful attacks steal credentials, install webshells, or deploy memory-resident VShell backdoors.
The activity has similarities to a campaign disclosed by Trellix, which used a filename parsing vulnerability akin to CVE-2023-2868 to deliver VShell; however, Proofpoint cannot currently link the reported activity to UNK_MassTraction.
Talos has found intrusions in enterprise networks of local governing bodies in the United States (U.S.), beginning January 2025 when initial exploitation first took place. UAT-6382 successfully exploited CVE-2025-0944, conducted reconnaissance and rapidly deployed a variety of web shells and custom-made malware to maintain long-term access.
The vulnerability, tracked as CVE-2026-1731, is an operating system command injection flaw that also impacts some older versions of BeyondTrust Privileged Remote Access. The flaw allows an attacker to execute arbitrary commands on a server without the need for credentials or any user interaction. | A critical vulnerability in BeyondTrust Remote Support is facing an increase in threat activity, with hackers deploying SparkRAT and vShell backdoors and using remote management tools to conduct reconnaissance...
16 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Once deployed it allows for delivery of additional arbitrary payloads such as Cobalt Strike or VShell stager, both observed in the reported attacks.
CVE-2023-48022 was used to hack into domestic AI-related research servers back in April, bouncing the shell and then executing bash scripts and plugins with the same origin as above, eventually loading Vshell.
We also found a VShell sample ... which communicates with this IP address.
We also found a VShell sample ... which communicates with this IP address.
A suspected China-nexus actor tracked as UNK_MassTraction exploited known Roundcube vulnerabilities to deploy web shells or VShell, a post-exploitation tool.
VShell is a full-fledged remote access trojan (RAT), programmed in Go... It has offensive capabilities such as capturing screenshots of victim computers, allows for browsing as well as uploading and downloading files, and the ability to remotely execute commands as a backdoor.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
La liste des TTPs détectés inclut « T1059 — Command and Scripting Interpreter »; VShell fournit un « Shell interactif ».
« Le loader télécharge un shellcode chiffré »; « Le payload est décodé (clé XOR 0x99) ».
“Inside is an executable with a near-identical document-style name, relying on Windows hiding known file extensions by default.”
La liste des TTPs détectés identifie « T1055 — Process Injection (Defense Evasion) » dans la chaîne SNOWLIGHT/VShell.
Uses HTTP and DNS (via DNS Tunneling T1071.004 ) for its C2 communications, in addition to raw TCP/UDP.
Les charges sont téléchargées depuis des URL HTTP, notamment « http://38.207.178.192:50813/EasyConnectUpdata_Log.txt » et « .../MySQL_LOG.txt »; la liste des TTPs inclut T1071.001.
The first piece of malicious code is a dropper embedding another vShell backdoor (v4.9.3) executed in memory, this time communicating via DNS tunneling .
“VShell can provide an interactive command shell, file transfer, screen capture, network discovery and tunneling.”
Network service 38.207.178.192:50812 [is the] SNOWLIGHT check-in and VShell transfer service.
« Le loader télécharge un shellcode chiffré » et « reçoit un payload de 4,65 Mo ».
To ensure persistence after lateral movements, Houken operators notably deployed the following GOREVERSE payloads... The following public tools were observed on the victims’ network... Backdoors and other persistence mechanisms: – GOREVERSE (reverse_ssh); – ReverseSSH; – SparkRAT;
168 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
119 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Post-exploitation tool reportedly deployed following exploitation of earlier, known Roundcube vulnerabilities.
A post-exploitation tool reportedly delivered following exploitation of Roundcube security flaws.
RAT livré par SNOWLIGHT, offrant un shell interactif, le transfert de fichiers, la capture d’écran, la découverte réseau et le tunneling. Il s’enregistre auprès du C2 en utilisant des communications chiffrées.
Remote-access trojan/framework providing encrypted command-and-control registration and capabilities for interactive command execution, file transfer, screen capture, network discovery, and tunneling. The observed sample registered and performed health checks, but operator actions were not captured.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.