Snowlight is a Linux-focused malware dropper associated with an infection chain that abuses maliciously crafted filenames to trigger Bash execution through unsafe automated file-handling routines and shell scripting patterns. Rather than relying on file contents alone, Snowlight embeds a payload in the filename so that operations such as filename expansion, evaluation, logging, or command substitution can execute attacker-controlled shell code. This tradecraft enables initial access through spam-delivered archives and is notable for exploiting operational weaknesses in shell-based workflows. Observed Snowlight activity includes delivery of a Bash downloader that detects victim CPU architecture, retrieves an architecture-specific ELF loader, and launches it using stealth-oriented fallback execution paths. The loader then contacts command-and-control infrastructure, decrypts a subsequent payload in memory, and executes it without writing the final stage to disk, while masquerading as a benign Linux kernel worker process. This behavior demonstrates defense evasion, post-exploitation staging, and fileless execution techniques. Snowlight has been observed preceding deployment of VShell, a Go-based Linux backdoor associated primarily with Chinese APT usage. In that infection chain, the final payload provided reverse shell access, file operations, process management, and network tunneling capabilities. High-confidence reporting supports Snowlight as the initial-stage dropper in this Linux intrusion sequence, but available information does not by itself establish Snowlight as a fully attributed standalone threat actor or provide corroborated details on a broader organizational structure, aliases beyond Snowlight, or a definitive sponsoring entity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.