SuperShell is an open-source command-and-control and reverse shell framework associated primarily with Chinese-speaking operators and repeatedly observed in intrusions linked to China-nexus threat activity. It has been described as a Go-based backdoor targeting Linux SSH servers, while also supporting cross-platform operation on Windows and Android. In hands-on intrusion activity, SuperShell has been used to provide remote command execution and persistent attacker access after compromise, and it has also appeared as operator tooling on exposed staging servers alongside credential-harvesting utilities, exploit material, and other offensive frameworks.
Observed deployment patterns show SuperShell being installed on internet-exposed Linux systems after SSH brute-force or dictionary attacks against weak credentials. Operators commonly use standard command-line transfer utilities to fetch and execute the payload after login, and some campaigns have paired SuperShell with XMRig to monetize compromised hosts through cryptocurrency mining. Separate reporting also ties SuperShell to exploitation-driven campaigns, including post-compromise deployment following exploitation of enterprise software vulnerabilities and large-scale compromise of exposed Gogs instances.
SuperShell is notable both as malware and as attacker infrastructure. Its web panels have been identified through reused interface artifacts, and the framework has been found on staging or command infrastructure used by multiple threat clusters. Public reporting has linked its use to UNC5174 and to other China-linked operations, while additional sightings place it in broader ecosystems involving access operations, espionage, and follow-on exploitation. Targeting associated with SuperShell use has included telecommunications providers, government and research organizations, critical infrastructure, and exposed internet-facing servers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On April 24, 2025, SAP disclosed CVE-2025-31324, a critical vulnerability with a CVSS score of 10.0 affecting the SAP NetWeaver's Visual Composer Framework, version 7.50. This vulnerability allows unauthenticated users to upload arbitrary files to an SAP NetWeaver application server, leading to potential remote code execution (RCE) and full system compromise. | The IP address 47.97.42[.]177 has also been associated with malware based on the open-source tool SUPERSHELL.
A vulnerability in self-hosted Git service Gogs is facing widespread exploitation, and no patch is available at this time. That's according to Wiz, which on Dec. 10 published research disclosing CVE-2025-8110, a bypass for a remote code execution vulnerability disclosed for Gogs last year (CVE-2024-55947).
Mandiant observed novel N-day exploitation of CVE-2023-46747 affecting F5 BIG-IP Traffic Management User Interface... UNC5174 has been observed attempting to sell access... following CVE-2023-46747 exploitation.
"This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174."
In February 2024, we observed exploitation of Connectwise ScreenConnect CVE-2024-1709 by the same actor... to compromise hundreds of institutions primarily in the U.S. and Canada.
"This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174."
"This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174."
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the threat actor has offered insights into their evolving offensive toolkit, including open-source C2 frameworks like antnium, GateSentinel, and SuperShell
Forescout Vedere Labs linked some of the ongoing attacks to a suspected Chinese threat actor they track as Chaya_004. The threat actor uses malicious infrastructure that includes "a network of servers hosting Supershell backdoors..."
"This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174."
22 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Mapping ... Resource Development Acquire Infrastructure: Virtual Private Server T1583.003 Alibaba Cloud VPS
Qakbot Command and Control Servers ... Qakbot server typically on port 443,993 or 995 ... Same ja3s across malicious servers.
MITRE ATT&CK Mapping ... Command and Control Application Layer Protocol: Web Protocols T1071.001 HTTP-based C2 panel
We observed attackers deploying other reverse shell tools... GOREVERSE has the following capabilities: ... Dynamic, local and remote forwarding ... Multiple network transports... We observed an attacker execute ... a Base64-encoded PowerShell script... Uses ssh.exe to establish a remote tunnel to the C2 server.
MITRE ATT&CK Mapping ... Command and Control Proxy: Multi-hop Proxy T1090.003 RSSH reverse tunnel over WebSocket
Infrastructure analysis also identified artifacts associated with the Metasploit and SuperShell C2 frameworks on the same server. This suggests the operator may leverage these frameworks to generate shellcode payloads delivered through PATCHCORD's in-memory execution capability.
1,568 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chinese-language command-and-control framework found on the exposed staging server as part of the operator toolkit.
An open-source command-and-control framework present in the threat actor's toolkit.
An open-source webshell management and C2 platform providing remote command execution, file management, and reverse shell capabilities. It was found on the staging server as part of the operator toolkit.
Command-and-control framework observed on the same subnet as multiple malware families.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.