SNOWLIGHT is a Linux-focused malware stager and downloader used to retrieve and launch follow-on implants, most notably VShell. It has been observed in exploit-driven intrusions against internet-facing applications and appliances, in mass web exploitation operations, and in targeted post-compromise activity. Reported use spans campaigns exploiting vulnerabilities in web frameworks, CMS platforms, mail servers, and enterprise edge devices. Multiple clusters have used SNOWLIGHT, including UNC5174, UNC6586, UAT-6382, UAT-8302, and other China-nexus or Chinese-speaking operators; it has also appeared in financially motivated access-broker activity, so its presence alone is not sufficient for attribution.
SNOWLIGHT commonly acts as an architecture-aware loader that detects the victim CPU type, retrieves a matching ELF payload from remote infrastructure, and executes it in memory or through lightweight staging logic. In several documented chains it delivered VShell, including variants loaded directly into memory and executed with stealth-oriented techniques. Observed tradecraft includes process masquerading as Linux kernel worker threads, anti-reinfection checks, use of shell scripts as an intermediate stage, fallback execution paths across writable directories, and network retrieval over channels including WebSocket. Some reporting also describes filename-based execution chains in which maliciously crafted archive filenames trigger Bash evaluation in unsafe file-handling workflows, leading to SNOWLIGHT deployment.
Operationally, SNOWLIGHT is associated with remote access enablement rather than destructive effects. It is used after initial compromise to establish a foothold and deploy more capable implants for command execution, proxying, tunneling, persistence, and broader post-exploitation. It has been seen on Linux servers, cloud-hosted workloads, Kubernetes-related environments, and compromised web infrastructure. In large-scale website compromise operations, operators used SNOWLIGHT to install VShell on their own infrastructure or on breached systems to maintain covert access. In espionage-oriented campaigns, it has served as a fallback or secondary access mechanism following exploitation of public-facing services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2025年12月3日(現地時間)、React Server Components(RSC)における認証不要のリモートコード実行の脆弱性(CVE-2025-55182)が公開されました。JPCERT/CCでは、この攻撃の被害報告を複数受けています。 | 2025-12-06 19:31 SNOWLIGHTのダウンローダー(javas)、CrossC2(rsyslo)の設置
Tracked as CVE-2026-34486 (CVSS score of 7.5), the third vulnerability added to the KEV catalog on Tuesday is an EncryptInterceptor bypass in Apache Tomcat that was patched in April. | Last week, SOCRadar warned that CVE-2026-34486 had been exploited by a Chinese threat actor in attacks involving the Snowlight malware family
WP File Manager CVE-2020-25213 Remove if not needed; file-manager plugins are high-value targets.
Ninja Forms CVE-2026-0740 Update and review form-related uploads and logs.
Plugin or platform CVE Action Breeze Cache CVE-2026-3844 Update immediately or disable until patched.
Joomla JCE CVE-2026-48907 Patch and inspect administrator upload paths.
Custom CSS JS PHP CVE-2026-6433 Verify only trusted admins can write executable code.
ThemeREX Addons CVE-2026-1969 Patch and review new files under writable theme/plugin paths.
Simple File List CVE-2025-34085 Remove unused installs and audit upload directories.
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... BerqWP CVE-2025-7443
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WPBookit CVE-2025-7852
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WavePlayer CVE-2025-12057
SNOWLIGHT: A generic stager for the VSHELL malware family, used by UAT-8302. Also used by UAT-6382, who exploited a Cityworks zero-day (CVE-2025-0994) to deploy VSHELL. | SNOWLIGHT: A generic stager for the VSHELL malware, used by UAT-8302. Also used by UAT-6382, who exploited a Cityworks zero-day (CVE-2025-0994) to deploy VSHELL.
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2025-12-06 19:31 SNOWLIGHTのダウンローダー(javas)、CrossC2(rsyslo)の設置
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Post-exploitation, attackers were observed to run arbitrary commands, such as reverse shells to known Cobalt Strike servers.
sex.sh xmrigのダウンロード用bashスクリプト / miner.sh xmrigの起動用bashスクリプト / javas SNOWLIGHTのダウンロード用bashスクリプト
The payload isn’t hidden inside the file content or a macro, it's encoded directly in the filename itself... The XOR key used is 0x99, a simple but effective method for evading static inspection.
"piping the downloaded content directly into sh, enabling fileless execution" (CL-STA-1015 slt).
the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list.
The decrypted shellcode is then injected into a combination of specified benign processes... If the process is named “mspaint.exe”, “browser”, or anything else, it will proceed to inject itself into dpapimg.exe, spoolsv.exe, etc.
"downloaders to retrieve payloads from attacker command and control (C2) infrastructure" and multiple C2 endpoints; KSwapDoor uses mesh routing and encryption
Command and Control T1071.001 Web Protocols HTTP used for staging, shell control, and callbacks
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
57 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware family reportedly involved in attacks exploiting Apache Tomcat CVE-2026-34486 by a Chinese threat actor.
Dropper used by the threat group to access or support its own infrastructure.
A stager used as follow-on tooling in the WP-SHELLSTORM campaign, associated with payload delivery after initial webshell compromise.
A dropper used to install VShell for persistent remote access on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.