VShell is a Go-based backdoor used for remote access and post-compromise control on Windows and Linux systems. It has been observed in intrusions involving web server exploitation, compromised mail servers, targeted attacks on MS-SQL environments, and large-scale web exploitation operations. Reported capabilities include interactive shell access, remote command execution, file management, and port forwarding, making it suitable for hands-on-keyboard post-exploitation and covert access to internal services.
VShell has been associated with multiple Chinese-speaking threat ecosystems, including both espionage-oriented and financially motivated operations, but its presence alone is not sufficient for attribution because it is also described as a commodity tool used across different clusters. It has been observed alongside tooling such as SNOWLIGHT, ShadowPad-related infrastructure, webshells, and reconnaissance frameworks. In some campaigns, VShell was delivered by a dropper or shell script and launched directly in memory; in others it was installed after exploitation of internet-facing applications such as Roundcube or after compromise of CMS and server infrastructure.
Documented tradecraft includes process masquerading on Linux by renaming itself to resemble a kernel worker thread in order to evade casual inspection. Communications and transport support reported for VShell include TCP, HTTP, and UDP. It has also been described as supporting plugins or auxiliary tooling for credential access, scanning, tunneling, and account creation in some operator workflows. Across observed incidents, VShell primarily functions as a stealthy persistence and remote administration implant used after initial access has already been obtained.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
После сбора данных IceCube использует вспомогательные компоненты для эксплуатации критической уязвимости десериализации в Roundcube — CVE-2025-49113. С ее помощью атакующие пытаются установить PHP-веб-шелл SquareShell, который позволяет удаленно выполнять команды.
WP File Manager CVE-2020-25213 Remove if not needed; file-manager plugins are high-value targets.
Simple File List CVE-2025-34085 Remove unused installs and audit upload directories.
Ninja Forms CVE-2026-0740 Update and review form-related uploads and logs.
Plugin or platform CVE Action Breeze Cache CVE-2026-3844 Update immediately or disable until patched.
Custom CSS JS PHP CVE-2026-6433 Verify only trusted admins can write executable code.
ThemeREX Addons CVE-2026-1969 Patch and review new files under writable theme/plugin paths.
Joomla JCE CVE-2026-48907 Patch and inspect administrator upload paths.
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WavePlayer CVE-2025-12057
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WPBookit CVE-2025-7852
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... BerqWP CVE-2025-7443
Threat actors exploit multiple vulnerabilities, including the CVE-2024-42009 cross-site scripting flaw. Exploitation triggers automatically when a user opens the email, requiring no further interaction. | Successful attacks steal credentials, install webshells, or deploy memory-resident VShell backdoors.
The activity has similarities to a campaign disclosed by Trellix, which used a filename parsing vulnerability akin to CVE-2023-2868 to deliver VShell; however, Proofpoint cannot currently link the reported activity to UNK_MassTraction.
CVE-2025-0994 is a high-severity deserialization vulnerability in Trimble Cityworks... Successfully exploiting CVE-2025-0994 can allow authenticated attackers to conduct remote code execution (RCE) against a target’s Microsoft Internet Information Services (IIS) web server. ... the vulnerability is being exploited to deliver custom Rust-based loaders capable of loading VShell and Cobalt Strike into memory. | IoCs shared by Trimble suggest that the vulnerability is being exploited to deliver custom Rust-based loaders capable of loading VShell and Cobalt Strike into memory.
Talos has found intrusions in enterprise networks of local governing bodies in the United States (U.S.), beginning January 2025 when initial exploitation first took place. UAT-6382 successfully exploited CVE-2025-0944, conducted reconnaissance and rapidly deployed a variety of web shells and custom-made malware to maintain long-term access.
The vulnerability, tracked as CVE-2026-1731, is an operating system command injection flaw that also impacts some older versions of BeyondTrust Privileged Remote Access. The flaw allows an attacker to execute arbitrary commands on a server without the need for credentials or any user interaction. | A critical vulnerability in BeyondTrust Remote Support is facing an increase in threat activity, with hackers deploying SparkRAT and vShell backdoors and using remote management tools to conduct reconnaissance...
The attackers downloaded the Bash script from hxxp://107.173.89[.]153:60051/slt ... These functionally identical executables serve as loaders for the VShell backdoor. | The threat actors leveraged the CVE‑2025‑55182 (React2Shell) vulnerability... React2Shell is a vulnerability in the Flight protocol, which facilitates client-server communication for React Server Components. The vulnerability stems from insecure deserialization... Under certain conditions, this can enable an attacker to execute arbitrary code on the server.
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
Forensic analysis identified a vulnerable Jenkins server (CVE-2024–23897) exposed on the internet as the source of the compromise. The latter served as the initial access for the threat actor...
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
14 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the attacker installed VShell and GotoHTTP to gain control over the infected system
В противном случае малварь загружает шелл-скрипт, который запускает прямо в памяти VShell — написанный на Go бэкдор, поддерживающий открытие интерактивного шелла и проброс портов.
For its own remote access, the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list.
Talos has so far found two types of payloads deployed by TetraLoader on the infected endpoints: ... VShell stager ... The payload received by the VShell stager is in fact the actual VShell implant. VShell is a GoLang-based implant that talks to its C2 and provides a wide variety of remote access trojan-based functionalities.
The group deploys NetDraft, a .NET-based backdoor linked to the FinDraft and SquidDoor family, alongside an updated version of the CloudSorcerer backdoor and the VSHELL implant.
SNOWLIGHT, a VShell stager... The attack chains culminate in the deployment of NetDraft, CloudSorcerer (version 3.0), and VShell.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner.
сам просмотр письма в уязвимой версии Roundcube запускает эксплуатацию старого XSS-бага CVE-2024-42009... После сбора данных IceCube использует вспомогательные компоненты для эксплуатации критической уязвимости десериализации в Roundcube — CVE-2025-49113.
While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner.
...бэкдор VShell, который маскировал имя своего процесса под системный поток ядра.
VShell is a backdoor malware developed in the Go programming language... supports protocols such as TCP, HTTP, and UDP for communication with the C&C server
Communication C2 : HTTPS avec URI imitant des assets statiques ( /assets/app.min.js , /assets/vendor.js , /assets/main.js )
VShell — написанный на Go бэкдор, поддерживающий открытие интерактивного шелла и проброс портов
VShell is a commodity Go-based backdoor that supports interactive shell access and port forwarding
120 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
101 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote administration/backdoor tool installed to maintain control over the compromised server.
VShell is referenced as a command-and-control framework that later operated on the same server, materially connected as shared attacker infrastructure.
A Go-based backdoor supporting Windows and Linux, with TCP/HTTP/UDP C2 communications and remote command execution and file management. It can also use plugins such as Mimikatz and Fscan.
Referenced as an active command-and-control server present in the infrastructure tied to the operation, relevant to attribution and operational context rather than as the main subject malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.