SNOWLIGHT is a cross-platform, architecture-aware loader and stager primarily used to retrieve and launch the VShell remote-access backdoor. Windows and Linux variants contact command-and-control infrastructure, transmit a short host check-in, retrieve an encrypted payload, decode it in memory, and transfer execution to VShell. Linux variants have selected payloads for x86, x86-64, ARM, and ARM64 systems and can execute decrypted payloads from anonymous in-memory file descriptors. Observed variants use anti-reinfection markers, process-name masquerading resembling Linux kernel worker threads, encrypted or XOR-obfuscated payload delivery, and anti-analysis checks. SNOWLIGHT has appeared in phishing-led Windows intrusions, exploit-driven compromises of internet-facing applications, and a Linux chain in which a malicious archive filename is interpreted by unsafe shell scripting. It has been used by or associated with UNC5174, UNC6586, UAT-6382, and UAT-8302, but its presence alone is insufficient to attribute an intrusion to a particular actor. Activity involving SNOWLIGHT has targeted academic researchers, government entities, and internet-facing enterprise and web infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Operators used exp.py, ysoserial, and a CommonsCollections6 gadget chain against Apache Tomcat 9.0.x to execute curl|sh commands that downloaded the SNOWLIGHT /slt stage loader; two compromises were confirmed. | The malware suite evaluated in this section has been definitively identified as SNOWLIGHT. This threat toolkit includes a shell dropper alongside four architecture-specific ELF loaders.
2025年12月3日(現地時間)、React Server Components(RSC)における認証不要のリモートコード実行の脆弱性(CVE-2025-55182)が公開されました。JPCERT/CCでは、この攻撃の被害報告を複数受けています。 | 2025-12-06 19:31 SNOWLIGHTのダウンローダー(javas)、CrossC2(rsyslo)の設置
WP File Manager CVE-2020-25213 Remove if not needed; file-manager plugins are high-value targets.
Ninja Forms CVE-2026-0740 Update and review form-related uploads and logs.
Plugin or platform CVE Action Breeze Cache CVE-2026-3844 Update immediately or disable until patched.
Joomla JCE CVE-2026-48907 Patch and inspect administrator upload paths.
Custom CSS JS PHP CVE-2026-6433 Verify only trusted admins can write executable code.
ThemeREX Addons CVE-2026-1969 Patch and review new files under writable theme/plugin paths.
Simple File List CVE-2025-34085 Remove unused installs and audit upload directories.
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... BerqWP CVE-2025-7443
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WPBookit CVE-2025-7852
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WavePlayer CVE-2025-12057
SNOWLIGHT: A generic stager for the VSHELL malware family, used by UAT-8302. Also used by UAT-6382, who exploited a Cityworks zero-day (CVE-2025-0994) to deploy VSHELL. | SNOWLIGHT: A generic stager for the VSHELL malware, used by UAT-8302. Also used by UAT-6382, who exploited a Cityworks zero-day (CVE-2025-0994) to deploy VSHELL.
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware suite evaluated in this section has been definitively identified as SNOWLIGHT. This threat toolkit includes a shell dropper alongside four architecture-specific ELF loaders.
The malware suite evaluated in this section has been definitively identified as SNOWLIGHT. This threat toolkit includes a shell dropper alongside four architecture-specific ELF loaders.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The toolkit comprises a purpose-built reconnaissance pipeline [and] eleven distinct exploit chains... Apache Tomcat, cPanel & WHM, Laravel, Microsoft Exchange ProxyShell, Apache Struts2, Atlassian Confluence, WebLogic-class targets, F5 BIG-IP TMUI, and Rejetto HFS.
The /slt endpoint functions as a stage loader, serving a script that executes directly on the target... delivered... using a conventional (curl … || wget …) | sh command sequence.
while ((n = recv(sock, buf, 4096, 0)) > 0) { for (i = 0; i < n; i++) buf[i] ^= 0x99; }
The malware uses a classic ROR-13 export-hashing routine... to locate necessary CRT, Winsock, and LoadLibraryA functions by scanning the Process Environment Block (PEB) dynamically at runtime.
« Le loader télécharge un shellcode chiffré »; « Le payload est décodé (clé XOR 0x99) ».
Inside is an executable with a near-identical document-style name, relying on Windows hiding known file extensions by default.
« un exécutable Windows dont le nom imite celui d’un document, exploitant le comportement par défaut de Windows qui masque les extensions de fichiers connues ».
La liste des TTPs détectés identifie « T1055 — Process Injection (Defense Evasion) » dans la chaîne SNOWLIGHT/VShell.
To fetch the payload without triggering alerts or spawning PowerShell or web browsers, the campaign utilizes certutil.exe -urlcache -split -f, a well-known Living-off-the-Land download method.
At the same time, it checks for an analysis environment, refuses systems with fewer than four CPU cores, and uses an unusual timing test before continuing.
[The loader] refuses systems with fewer than four CPU cores.
At the same time, it checks for an analysis environment, refuses systems with fewer than four CPU cores, and uses an unusual timing test before continuing.
Les charges sont téléchargées depuis des URL HTTP, notamment « http://38.207.178.192:50813/EasyConnectUpdata_Log.txt » et « .../MySQL_LOG.txt »; la liste des TTPs inclut T1071.001.
Network service 38.207.178.192:50812 [is the] SNOWLIGHT check-in and VShell transfer service.
59 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
62 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader fileless diffusé au moyen d’une pièce jointe ZIP de spearphishing se faisant passer pour un CV. Il effectue des contrôles anti-analyse (notamment CPU et timing), télécharge et exécute du shellcode chiffré en mémoire, puis contacte le C2 afin de récupérer le payload VShell.
Memory-resident shellcode loader that performs anti-analysis checks, contacts command-and-control infrastructure, downloads and decrypts a payload, and transfers execution to VShell. It also uses a TEMPde.log marker described as a kill-switch or operator-exclusion marker.
Memory-resident Windows shellcode loader delivered through a fake resume executable. It performs anti-analysis checks, downloads encrypted shellcode from a staging server, checks in to C2, receives an encrypted payload, decodes it, and transfers execution to VShell.
Windows memory-resident shellcode that contacts a command server, sends a system check-in, receives and decodes a payload, then transfers execution to VShell. It is delivered by a resume-themed executable and includes anti-analysis checks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.