VShell is a Go-based, cross-platform remote-access trojan and backdoor supporting Windows, Linux, and macOS/Darwin systems. It provides interactive command execution, file browsing and transfer, screenshot capture, network discovery, and proxy/tunneling functions, including SOCKS5, HTTP, and TCP/UDP proxying for pivoting and data movement. It supports multiple command-and-control transports, including TCP, UDP, WebSockets, DNS, DNS-over-HTTPS, DNS-over-TLS, and object-storage services, and uses encrypted communications.
VShell is commonly deployed after compromise of public-facing systems, including edge appliances and webmail infrastructure, and has also been delivered through spearphishing lures as a later-stage payload. It supports shellcode, stager, and full-beacon payload formats, in-memory execution, plugins, and persistence features. Versions have incorporated anti-sandbox functionality, encrypted traffic, reduced command logging, and eBPF-related support. VShell has been used in long-running espionage, pre-positioning, and access-brokering activity, as well as financially motivated intrusions. It has been associated with UNC5174, Houken, UNK_MassTraction, and other clusters, but its use alone is not sufficient to attribute an intrusion to any one actor. Victims have included government, healthcare, military, research, academic, telecommunications, finance, transport, and technology organizations worldwide.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This one-liner functionality has commonly been used as payloads for or following remote command execution (RCE) exploits such as CVE-2025-3132418. | VShell is a full-fledged remote access trojan (RAT), programmed in Go... It has offensive capabilities such as capturing screenshots of victim computers, allows for browsing as well as uploading and downloading files, and the ability to remotely execute commands as a backdoor.
Forensic analysis identified a vulnerable Jenkins server (CVE-2024–23897) exposed on the internet as the source of the compromise. The latter served as the initial access for the threat actor...
As part of these long-running activities, we exceptionally observed adversaries trigger novel vulnerabilities such as VMware’s CVE-2025-41244 local privilege escalation. | VShell is a full-fledged remote access trojan (RAT), programmed in Go... It has offensive capabilities such as capturing screenshots of victim computers, allows for browsing as well as uploading and downloading files, and the ability to remotely execute commands as a backdoor.
NVISO observed amongst others, UNC5174’s reliance on remote code execution vulnerabilities such as CVE-2024-36401 (GeoServer33). | VShell is a full-fledged remote access trojan (RAT), programmed in Go... It has offensive capabilities such as capturing screenshots of victim computers, allows for browsing as well as uploading and downloading files, and the ability to remotely execute commands as a backdoor.
After gaining access to Roundcube servers, UNK_MassTraction exploited CVE-2025-49113, a deserialization vulnerability, to deploy a webshell or install the VShell backdoor in memory.
WP File Manager CVE-2020-25213 Remove if not needed; file-manager plugins are high-value targets.
Simple File List CVE-2025-34085 Remove unused installs and audit upload directories.
Ninja Forms CVE-2026-0740 Update and review form-related uploads and logs.
Plugin or platform CVE Action Breeze Cache CVE-2026-3844 Update immediately or disable until patched.
Custom CSS JS PHP CVE-2026-6433 Verify only trusted admins can write executable code.
ThemeREX Addons CVE-2026-1969 Patch and review new files under writable theme/plugin paths.
Joomla JCE CVE-2026-48907 Patch and inspect administrator upload paths.
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WavePlayer CVE-2025-12057
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WPBookit CVE-2025-7852
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... BerqWP CVE-2025-7443
Threat actors exploit multiple vulnerabilities, including the CVE-2024-42009 cross-site scripting flaw. Exploitation triggers automatically when a user opens the email, requiring no further interaction. | Successful attacks steal credentials, install webshells, or deploy memory-resident VShell backdoors.
The activity has similarities to a campaign disclosed by Trellix, which used a filename parsing vulnerability akin to CVE-2023-2868 to deliver VShell; however, Proofpoint cannot currently link the reported activity to UNK_MassTraction.
CVE-2025-0994 is a high-severity deserialization vulnerability in Trimble Cityworks... Successfully exploiting CVE-2025-0994 can allow authenticated attackers to conduct remote code execution (RCE) against a target’s Microsoft Internet Information Services (IIS) web server. ... the vulnerability is being exploited to deliver custom Rust-based loaders capable of loading VShell and Cobalt Strike into memory. | IoCs shared by Trimble suggest that the vulnerability is being exploited to deliver custom Rust-based loaders capable of loading VShell and Cobalt Strike into memory.
Talos has found intrusions in enterprise networks of local governing bodies in the United States (U.S.), beginning January 2025 when initial exploitation first took place. UAT-6382 successfully exploited CVE-2025-0944, conducted reconnaissance and rapidly deployed a variety of web shells and custom-made malware to maintain long-term access.
The vulnerability, tracked as CVE-2026-1731, is an operating system command injection flaw that also impacts some older versions of BeyondTrust Privileged Remote Access. The flaw allows an attacker to execute arbitrary commands on a server without the need for credentials or any user interaction. | A critical vulnerability in BeyondTrust Remote Support is facing an increase in threat activity, with hackers deploying SparkRAT and vShell backdoors and using remote management tools to conduct reconnaissance...
The attackers downloaded the Bash script from hxxp://107.173.89[.]153:60051/slt ... These functionally identical executables serve as loaders for the VShell backdoor. | The threat actors leveraged the CVE‑2025‑55182 (React2Shell) vulnerability... React2Shell is a vulnerability in the Flight protocol, which facilitates client-server communication for React Server Components. The vulnerability stems from insecure deserialization... Under certain conditions, this can enable an attacker to execute arbitrary code on the server.
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
15 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNK_MassTraction repeatedly exploited Roundcube vulnerabilities to infiltrate university networks and used IceCube, SquareShell, and VShell.
Houken operators used open-source tools previously detailed as part of UNC5174 intrusion set such as: GOREVERSE, VShell, fscan or ffuff.
VShell is a full-fledged remote access trojan (RAT), programmed in Go... It has offensive capabilities such as capturing screenshots of victim computers, allows for browsing as well as uploading and downloading files, and the ability to remotely execute commands as a backdoor.
the attacker installed VShell and GotoHTTP to gain control over the infected system
Talos has so far found two types of payloads deployed by TetraLoader on the infected endpoints: ... VShell stager ... The payload received by the VShell stager is in fact the actual VShell implant. VShell is a GoLang-based implant that talks to its C2 and provides a wide variety of remote access trojan-based functionalities.
The group deploys NetDraft, a .NET-based backdoor linked to the FinDraft and SquidDoor family, alongside an updated version of the CloudSorcerer backdoor and the VSHELL implant.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
« Le loader télécharge un shellcode chiffré »; « Le payload est décodé (clé XOR 0x99) ».
“Inside is an executable with a near-identical document-style name, relying on Windows hiding known file extensions by default.”
Uses HTTP and DNS (via DNS Tunneling T1071.004 ) for its C2 communications, in addition to raw TCP/UDP.
Les charges sont téléchargées depuis des URL HTTP, notamment « http://38.207.178.192:50813/EasyConnectUpdata_Log.txt » et « .../MySQL_LOG.txt »; la liste des TTPs inclut T1071.001.
The first piece of malicious code is a dropper embedding another vShell backdoor (v4.9.3) executed in memory, this time communicating via DNS tunneling .
“VShell can provide an interactive command shell, file transfer, screen capture, network discovery and tunneling.”
Network service 38.207.178.192:50812 [is the] SNOWLIGHT check-in and VShell transfer service.
« Le loader télécharge un shellcode chiffré » et « reçoit un payload de 4,65 Mo ».
To ensure persistence after lateral movements, Houken operators notably deployed the following GOREVERSE payloads... The following public tools were observed on the victims’ network... Backdoors and other persistence mechanisms: – GOREVERSE (reverse_ssh); – ReverseSSH; – SparkRAT;
143 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
113 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT livré par SNOWLIGHT, offrant un shell interactif, le transfert de fichiers, la capture d’écran, la découverte réseau et le tunneling. Il s’enregistre auprès du C2 en utilisant des communications chiffrées.
Remote-access trojan/framework providing encrypted command-and-control registration and capabilities for interactive command execution, file transfer, screen capture, network discovery, and tunneling. The observed sample registered and performed health checks, but operator actions were not captured.
Remote-access trojan/framework deployed by SNOWLIGHT. It registers with C2 over encrypted traffic and supports interactive shell access, file transfers, screen capture, network discovery, and tunneling. The observed sample completed registration and health checks, but operator activity was not captured.
Remote-access trojan/framework providing an interactive command shell, file transfer, screen capture, network discovery, and tunneling. In this incident, its registration and health checks were observed, but no operator commands or lateral movement were captured.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.