VShell is a publicly available Go-based backdoor and remote access implant used in intrusions across Linux, Windows, and macOS environments. It is commonly described as a fully featured remote administration implant and has been repeatedly observed in operations linked to Chinese-speaking and China-aligned threat actors, although its availability and use in criminal ecosystems mean its presence alone is not sufficient for attribution.
VShell provides post-compromise remote access capabilities including interactive shell access, arbitrary command execution, file operations, port forwarding, screenshot capture, and proxying functionality. Multiple reports describe it as supporting broad remote administration and post-exploitation control on compromised systems, especially internet-facing servers. In several observed Linux deployments, VShell was executed directly in memory and paired with process masquerading to reduce visibility, including renaming itself to resemble a kernel worker thread. It has also been delivered through stagers and custom loaders that decrypt or decode the implant in memory before execution.
Observed delivery chains show VShell used as a follow-on payload after exploitation rather than as a primary initial-access mechanism. It has been deployed after exploitation of public-facing applications including Roundcube, Trimble Cityworks, BeyondTrust Remote Support, and mass exploitation of vulnerable WordPress and other CMS components. In these campaigns, operators used webshells, shell scripts, Rust-based loaders, or ELF droppers such as SNOWLIGHT and TetraLoader to install or inject VShell. Some campaigns used it as a fallback persistence and remote-access option when webshell deployment failed.
Victimology associated with VShell spans universities, government and public-sector networks, financial services, healthcare, legal services, technology organizations, utilities-related environments, and broadly exposed web infrastructure. It has appeared in espionage-oriented campaigns targeting research institutions and public-sector entities as well as financially motivated mass-exploitation and access-brokerage operations. The malware’s cross-platform support, in-memory execution patterns, and compatibility with broader Chinese-speaking offensive tooling ecosystems have made it a recurring implant in both targeted and opportunistic intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
После сбора данных IceCube использует вспомогательные компоненты для эксплуатации критической уязвимости десериализации в Roundcube — CVE-2025-49113. С ее помощью атакующие пытаются установить PHP-веб-шелл SquareShell, который позволяет удаленно выполнять команды.
WP File Manager CVE-2020-25213 Remove if not needed; file-manager plugins are high-value targets.
Simple File List CVE-2025-34085 Remove unused installs and audit upload directories.
Ninja Forms CVE-2026-0740 Update and review form-related uploads and logs.
Plugin or platform CVE Action Breeze Cache CVE-2026-3844 Update immediately or disable until patched.
Custom CSS JS PHP CVE-2026-6433 Verify only trusted admins can write executable code.
ThemeREX Addons CVE-2026-1969 Patch and review new files under writable theme/plugin paths.
Joomla JCE CVE-2026-48907 Patch and inspect administrator upload paths.
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WavePlayer CVE-2025-12057
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WPBookit CVE-2025-7852
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... BerqWP CVE-2025-7443
Threat actors exploit multiple vulnerabilities, including the CVE-2024-42009 cross-site scripting flaw. Exploitation triggers automatically when a user opens the email, requiring no further interaction. | Successful attacks steal credentials, install webshells, or deploy memory-resident VShell backdoors.
The activity has similarities to a campaign disclosed by Trellix, which used a filename parsing vulnerability akin to CVE-2023-2868 to deliver VShell; however, Proofpoint cannot currently link the reported activity to UNK_MassTraction.
CVE-2025-0994 is a high-severity deserialization vulnerability in Trimble Cityworks... Successfully exploiting CVE-2025-0994 can allow authenticated attackers to conduct remote code execution (RCE) against a target’s Microsoft Internet Information Services (IIS) web server. ... the vulnerability is being exploited to deliver custom Rust-based loaders capable of loading VShell and Cobalt Strike into memory. | IoCs shared by Trimble suggest that the vulnerability is being exploited to deliver custom Rust-based loaders capable of loading VShell and Cobalt Strike into memory.
Talos has found intrusions in enterprise networks of local governing bodies in the United States (U.S.), beginning January 2025 when initial exploitation first took place. UAT-6382 successfully exploited CVE-2025-0944, conducted reconnaissance and rapidly deployed a variety of web shells and custom-made malware to maintain long-term access.
The vulnerability, tracked as CVE-2026-1731, is an operating system command injection flaw that also impacts some older versions of BeyondTrust Privileged Remote Access. The flaw allows an attacker to execute arbitrary commands on a server without the need for credentials or any user interaction. | A critical vulnerability in BeyondTrust Remote Support is facing an increase in threat activity, with hackers deploying SparkRAT and vShell backdoors and using remote management tools to conduct reconnaissance...
The attackers downloaded the Bash script from hxxp://107.173.89[.]153:60051/slt ... These functionally identical executables serve as loaders for the VShell backdoor. | The threat actors leveraged the CVE‑2025‑55182 (React2Shell) vulnerability... React2Shell is a vulnerability in the Flight protocol, which facilitates client-server communication for React Server Components. The vulnerability stems from insecure deserialization... Under certain conditions, this can enable an attacker to execute arbitrary code on the server.
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
Forensic analysis identified a vulnerable Jenkins server (CVE-2024–23897) exposed on the internet as the source of the compromise. The latter served as the initial access for the threat actor...
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
В противном случае малварь загружает шелл-скрипт, который запускает прямо в памяти VShell — написанный на Go бэкдор, поддерживающий открытие интерактивного шелла и проброс портов.
For its own remote access, the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list.
Talos has so far found two types of payloads deployed by TetraLoader on the infected endpoints: ... VShell stager ... The payload received by the VShell stager is in fact the actual VShell implant. VShell is a GoLang-based implant that talks to its C2 and provides a wide variety of remote access trojan-based functionalities.
The group deploys NetDraft, a .NET-based backdoor linked to the FinDraft and SquidDoor family, alongside an updated version of the CloudSorcerer backdoor and the VSHELL implant.
SNOWLIGHT, a VShell stager... The attack chains culminate in the deployment of NetDraft, CloudSorcerer (version 3.0), and VShell.
VELETRIX carries a VShell shellcode which is an Offensive Security Tool, like Meterpreter, Cobalt Strike among others, which means that, when executed, it will communicate with the Command and Control server.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
сам просмотр письма в уязвимой версии Roundcube запускает эксплуатацию старого XSS-бага CVE-2024-42009... После сбора данных IceCube использует вспомогательные компоненты для эксплуатации критической уязвимости десериализации в Roundcube — CVE-2025-49113.
A parallel Java infrastructure campaign that stole configuration files and secrets.
CVE-2025-0994 is a high-severity deserialization vulnerability in Trimble Cityworks... Successfully exploiting CVE-2025-0994 can allow authenticated attackers to conduct remote code execution (RCE) against a target’s Microsoft Internet Information Services (IIS) web server.
TencShell is a Go-based implant... HTTP GET requests to port 1111 on 112.213.124[.]132 triggered the download of a previously unreported Linux/ARM 32-bit binary, HSEWH-Ur. The Golang-compiled, statically linked executable beacons over WebSocket to port 4081 on the same host
Command and Control T1071.001 Web Protocols HTTP used for staging, shell control, and callbacks
VShell — написанный на Go бэкдор, поддерживающий открытие интерактивного шелла и проброс портов
VShell is a commodity Go-based backdoor that supports interactive shell access and port forwarding
94 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
93 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote system administration tool present on the campaign infrastructure and used as part of the offensive toolkit.
Go-based backdoor executed in memory that supports an interactive shell and port forwarding when web-shell installation fails.
VSHell6
An implant used in the campaign that provides persistence and disguises itself via process masquerading, including names like [kworker/X:Y], to blend in with Linux kernel worker processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.