SNOWLIGHT is a Linux-focused stager and downloader used to retrieve and launch follow-on implants, most notably the VShell backdoor. It has been observed in exploit-driven intrusions against internet-facing applications and in post-exploitation chains where attackers already obtained code execution on exposed servers. Its core role is to act as a lightweight intermediary that detects the victim system’s CPU architecture, fetches a matching payload from command-and-control infrastructure, and executes it, often with an emphasis on in-memory or low-visibility execution.
SNOWLIGHT has been associated with multiple China-nexus intrusion clusters and overlapping tooling ecosystems, including UNC5174, UNC6586, UAT-6382, UAT-8302, and activity linked to broader Chinese-speaking operations. It has also appeared in mass exploitation campaigns targeting vulnerable web applications and CMS infrastructure, where it served as a follow-on payload after initial compromise. Reported use spans both targeted espionage-oriented intrusions and opportunistic exploitation activity.
Behaviorally, SNOWLIGHT functions as a dropper or stager for VShell and related payloads. Observed variants and delivery chains select architecture-specific ELF binaries, broaden execution reliability through shell-script logic, and launch payloads with stealth-oriented methods such as background execution and process masquerading. In several observed cases, the resulting implant disguised itself as a Linux kernel worker thread to blend into process listings. Some reporting also describes SNOWLIGHT as memory-based or fileless after retrieval, with the final payload decrypted or executed in memory rather than written back to disk.
A notable infection pattern linked to SNOWLIGHT involves Linux shell execution triggered by maliciously crafted filenames. In that tradecraft, an archive contains a filename embedding shell-compatible commands; unsafe automated file-handling routines or shell scripting patterns can interpret the filename and execute a Bash downloader, which then retrieves SNOWLIGHT. Other observed deployments used exploitation of public-facing vulnerabilities in products such as SAP NetWeaver, Roundcube, Cityworks, React and Next.js workloads, and vulnerable CMS plugins, after which SNOWLIGHT was used to establish more durable remote access through VShell.
SNOWLIGHT is best characterized as a generic VShell stager rather than a full-featured backdoor in its own right. Its operational value lies in payload delivery, architecture awareness, stealthy execution, and enabling persistent remote access through subsequent implants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
WP File Manager CVE-2020-25213 Remove if not needed; file-manager plugins are high-value targets.
Ninja Forms CVE-2026-0740 Update and review form-related uploads and logs.
Plugin or platform CVE Action Breeze Cache CVE-2026-3844 Update immediately or disable until patched.
Joomla JCE CVE-2026-48907 Patch and inspect administrator upload paths.
Custom CSS JS PHP CVE-2026-6433 Verify only trusted admins can write executable code.
ThemeREX Addons CVE-2026-1969 Patch and review new files under writable theme/plugin paths.
Simple File List CVE-2025-34085 Remove unused installs and audit upload directories.
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... BerqWP CVE-2025-7443
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WPBookit CVE-2025-7852
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WavePlayer CVE-2025-12057
SNOWLIGHT: A generic stager for the VSHELL malware family, used by UAT-8302. Also used by UAT-6382, who exploited a Cityworks zero-day (CVE-2025-0994) to deploy VSHELL. | SNOWLIGHT: A generic stager for the VSHELL malware, used by UAT-8302. Also used by UAT-6382, who exploited a Cityworks zero-day (CVE-2025-0994) to deploy VSHELL.
Since exploitation began last week, our team at Google Threat Intelligence Group (GTIG) has been tracking widespread activity as multiple threat clusters race to leverage React2Shell (CVE-2025-55182). | Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For its own remote access, the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Post-exploitation, attackers were observed to run arbitrary commands, such as reverse shells to known Cobalt Strike servers.
The fallback channel executes a shell script that sets up the execution of another loader that Google tracks as SnowLight.
The payload isn’t hidden inside the file content or a macro, it's encoded directly in the filename itself... The XOR key used is 0x99, a simple but effective method for evading static inspection.
"piping the downloaded content directly into sh, enabling fileless execution" (CL-STA-1015 slt).
the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list.
The decrypted shellcode is then injected into a combination of specified benign processes... If the process is named “mspaint.exe”, “browser”, or anything else, it will proceed to inject itself into dpapimg.exe, spoolsv.exe, etc.
"downloaders to retrieve payloads from attacker command and control (C2) infrastructure" and multiple C2 endpoints; KSwapDoor uses mesh routing and encryption
Command and Control T1071.001 Web Protocols HTTP used for staging, shell control, and callbacks
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
52 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stager used as follow-on tooling in the WP-SHELLSTORM campaign, associated with payload delivery after initial webshell compromise.
A dropper used to install VShell for persistent remote access on compromised systems.
A dropper used in the campaign for remote access. It selects payloads based on CPU architecture and retrieves a matching implant over WebSocket traffic to reduce detection.
A loader used as a fallback execution channel in exploit-driven intrusions attributed to Chinese adversaries.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.