SNOWLIGHT is a cross-platform downloader and payload stager used to retrieve and execute secondary implants, particularly the VShell remote-access trojan. It is available as a default stager in the VShell framework and has Windows and Linux implementations. Linux deployment scripts select architecture-specific ELF loaders for x86, x86-64, ARM, and ARM64 systems.
SNOWLIGHT contacts command-and-control infrastructure, transmits an initial check-in or architecture identifier, retrieves an encoded payload, decodes it, and transfers execution to the implant. Observed variants use XOR-obfuscated payloads. Linux loaders support fileless execution through anonymous memory-backed file descriptors and fexecve, while Windows shellcode variants participate in memory-resident infection chains. Additional evasion features include dynamically resolving Windows APIs through Process Environment Block traversal and export hashing. Some variants check for a local exclusion marker and terminate without contacting command-and-control infrastructure when it is present.
Deployment has followed exploitation of internet-facing applications, including React Server Components CVE-2025-55182, BeyondTrust Privileged Remote Access and Remote Support CVE-2026-1731, and Apache Tomcat vulnerabilities. SNOWLIGHT has also been delivered through spearphishing attachments disguised as academic application documents, targeting researchers working in applied artificial intelligence, electrical engineering, power grids, and renewable energy. These attacks use a decoy résumé and an upstream loader to introduce SNOWLIGHT before deploying VShell.
SNOWLIGHT has been associated with the China-nexus intrusion clusters UNC5174 and UNC6586 and has appeared in China-aligned university espionage activity tracked as UNK_MassTraction. Chinese-speaking financially motivated operators have also used it to install VShell on their own infrastructure. Its availability within VShell and use across distinct activity clusters mean that its presence alone does not establish threat-actor attribution. Remote-access, credential-theft, and other downstream implant functions are distinct from SNOWLIGHT's staging role.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“More recently, Earth Lamia also exploited CVE-2025-31324 (SAP NetWeaver Visual Composer unauthenticated file upload vulnerability).” The attribution discussion connects exploitation campaigns to Cobalt Strike infrastructure and a VShell deployment involving the SNOWLIGHT stager.
Injection de commandes OS non authentifiée dans BeyondTrust Privileged Remote Access (PRA) et Remote Support, découverte par l’agent IA tiers Hacktron AI. Dans les 4 jours suivant la divulgation, un premier cluster de menaces l’exploitait ; 5 clusters supplémentaires dans les 7 jours. | Activités post-exploitation observées : élévation de privilèges, exfiltration de données, dépôt de payloads secondaires (SNOWLIGHT, SPARKRAT, cryptomineurs).
Operators used exp.py, ysoserial, and a CommonsCollections6 gadget chain against Apache Tomcat 9.0.x to execute curl|sh commands that downloaded the SNOWLIGHT /slt stage loader; two compromises were confirmed. | The malware suite evaluated in this section has been definitively identified as SNOWLIGHT. This threat toolkit includes a shell dropper alongside four architecture-specific ELF loaders.
2025年12月3日(現地時間)、React Server Components(RSC)における認証不要のリモートコード実行の脆弱性(CVE-2025-55182)が公開されました。JPCERT/CCでは、この攻撃の被害報告を複数受けています。 | 2025-12-06 19:31 SNOWLIGHTのダウンローダー(javas)、CrossC2(rsyslo)の設置
WP File Manager CVE-2020-25213 Remove if not needed; file-manager plugins are high-value targets.
Ninja Forms CVE-2026-0740 Update and review form-related uploads and logs.
Plugin or platform CVE Action Breeze Cache CVE-2026-3844 Update immediately or disable until patched.
Joomla JCE CVE-2026-48907 Patch and inspect administrator upload paths.
Custom CSS JS PHP CVE-2026-6433 Verify only trusted admins can write executable code.
ThemeREX Addons CVE-2026-1969 Patch and review new files under writable theme/plugin paths.
Simple File List CVE-2025-34085 Remove unused installs and audit upload directories.
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... BerqWP CVE-2025-7443
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WPBookit CVE-2025-7852
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WavePlayer CVE-2025-12057
SNOWLIGHT: A generic stager for the VSHELL malware family, used by UAT-8302. Also used by UAT-6382, who exploited a Cityworks zero-day (CVE-2025-0994) to deploy VSHELL. | SNOWLIGHT: A generic stager for the VSHELL malware, used by UAT-8302. Also used by UAT-6382, who exploited a Cityworks zero-day (CVE-2025-0994) to deploy VSHELL.
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SNOWLIGHT is also one of default stagers in the VShell framework.
The malware suite evaluated in this section has been definitively identified as SNOWLIGHT. This threat toolkit includes a shell dropper alongside four architecture-specific ELF loaders.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware uses a classic ROR-13 export-hashing routine... to locate necessary CRT, Winsock, and LoadLibraryA functions by scanning the Process Environment Block (PEB) dynamically at runtime.
« Le loader télécharge un shellcode chiffré »; « Le payload est décodé (clé XOR 0x99) ».
Inside is an executable with a near-identical document-style name, relying on Windows hiding known file extensions by default.
« un exécutable Windows dont le nom imite celui d’un document, exploitant le comportement par défaut de Windows qui masque les extensions de fichiers connues ».
La liste des TTPs détectés identifie « T1055 — Process Injection (Defense Evasion) » dans la chaîne SNOWLIGHT/VShell.
At the same time, it checks for an analysis environment, refuses systems with fewer than four CPU cores, and uses an unusual timing test before continuing.
[The loader] refuses systems with fewer than four CPU cores.
At the same time, it checks for an analysis environment, refuses systems with fewer than four CPU cores, and uses an unusual timing test before continuing.
Les charges sont téléchargées depuis des URL HTTP, notamment « http://38.207.178.192:50813/EasyConnectUpdata_Log.txt » et « .../MySQL_LOG.txt »; la liste des TTPs inclut T1071.001.
Network service 38.207.178.192:50812 [is the] SNOWLIGHT check-in and VShell transfer service.
59 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
67 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Payload deployed following exploitation of the BeyondTrust Privileged Remote Access and Remote Support command-injection vulnerability; the content provides no further functional details.
Named as a secondary payload deployed following exploitation of CVE-2026-1731 in BeyondTrust Privileged Remote Access and Remote Support. The content does not specify SNOWLIGHT's capabilities or establish that it directly exploited the vulnerability.
A named secondary payload dropped by threat clusters after exploiting the BeyondTrust vulnerability CVE-2026-1731.
Loader fileless diffusé au moyen d’une pièce jointe ZIP de spearphishing se faisant passer pour un CV. Il effectue des contrôles anti-analyse (notamment CPU et timing), télécharge et exécute du shellcode chiffré en mémoire, puis contacte le C2 afin de récupérer le payload VShell.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.