SNOWLIGHT is a Linux-focused stager and dropper used to retrieve and launch follow-on implants, most notably VShell. It has been observed as an architecture-aware ELF loader and as part of exploit-driven intrusion chains in which a shell script or downloader selects a payload matching the victim CPU architecture, fetches it from command-and-control infrastructure, and executes it with stealth-oriented fallback logic. Reported implementations broaden execution paths across writable directories, use background execution, and in some cases decrypt and execute the next-stage payload in memory while masquerading as a Linux kernel worker process to reduce visibility.
SNOWLIGHT has been associated with multiple China-nexus or Chinese-speaking threat clusters, including UNC5174, UNC6586, UAT-6382, and UAT-8302, and has also appeared in broader Chinese-linked exploitation ecosystems and access-broker activity. It has been deployed following exploitation of internet-facing applications and appliances, including campaigns involving Apache Tomcat, SAP NetWeaver, Cityworks, and React2Shell, as well as in Roundcube intrusion chains where it served as a fallback loader when webshell deployment failed. Separate reporting also links SNOWLIGHT to mass web exploitation operations targeting vulnerable CMS platforms, where it was used to install VShell for operator remote access.
Behaviorally, SNOWLIGHT functions primarily as a staging component rather than a full-featured access implant. Its core role is to download and execute additional payloads, especially VShell, enabling persistent remote access and post-exploitation activity by the operator. Observed tradecraft includes CPU architecture detection, stealthy execution, process masquerading, anti-reinfection checks, and memory-resident execution of follow-on malware. Some reporting also aligns SNOWLIGHT activity with malicious filename abuse and Bash-based execution chains on Linux, where crafted filenames can trigger shell interpretation and launch the downloader through unsafe automated file-handling routines.
SNOWLIGHT targets Linux systems and has been seen in campaigns against government entities, universities, enterprise web infrastructure, and large populations of internet-facing servers. Its repeated use across both espionage-oriented and financially motivated operations indicates that it is a reusable staging utility within a broader tooling ecosystem centered on VShell and related post-compromise capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Tracked as CVE-2026-34486 (CVSS score of 7.5), the third vulnerability added to the KEV catalog on Tuesday is an EncryptInterceptor bypass in Apache Tomcat that was patched in April. | Last week, SOCRadar warned that CVE-2026-34486 had been exploited by a Chinese threat actor in attacks involving the Snowlight malware family
WP File Manager CVE-2020-25213 Remove if not needed; file-manager plugins are high-value targets.
Ninja Forms CVE-2026-0740 Update and review form-related uploads and logs.
Plugin or platform CVE Action Breeze Cache CVE-2026-3844 Update immediately or disable until patched.
Joomla JCE CVE-2026-48907 Patch and inspect administrator upload paths.
Custom CSS JS PHP CVE-2026-6433 Verify only trusted admins can write executable code.
ThemeREX Addons CVE-2026-1969 Patch and review new files under writable theme/plugin paths.
Simple File List CVE-2025-34085 Remove unused installs and audit upload directories.
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... BerqWP CVE-2025-7443
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WPBookit CVE-2025-7852
For WordPress/Joomla specifically, the plugins below were directly targeted in this campaign and should be updated... WavePlayer CVE-2025-12057
SNOWLIGHT: A generic stager for the VSHELL malware family, used by UAT-8302. Also used by UAT-6382, who exploited a Cityworks zero-day (CVE-2025-0994) to deploy VSHELL. | SNOWLIGHT: A generic stager for the VSHELL malware, used by UAT-8302. Also used by UAT-6382, who exploited a Cityworks zero-day (CVE-2025-0994) to deploy VSHELL.
Since exploitation began last week, our team at Google Threat Intelligence Group (GTIG) has been tracking widespread activity as multiple threat clusters race to leverage React2Shell (CVE-2025-55182). | Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For its own remote access, the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Post-exploitation, attackers were observed to run arbitrary commands, such as reverse shells to known Cobalt Strike servers.
The fallback channel executes a shell script that sets up the execution of another loader that Google tracks as SnowLight.
The payload isn’t hidden inside the file content or a macro, it's encoded directly in the filename itself... The XOR key used is 0x99, a simple but effective method for evading static inspection.
"piping the downloaded content directly into sh, enabling fileless execution" (CL-STA-1015 slt).
the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list.
The decrypted shellcode is then injected into a combination of specified benign processes... If the process is named “mspaint.exe”, “browser”, or anything else, it will proceed to inject itself into dpapimg.exe, spoolsv.exe, etc.
"downloaders to retrieve payloads from attacker command and control (C2) infrastructure" and multiple C2 endpoints; KSwapDoor uses mesh routing and encryption
Command and Control T1071.001 Web Protocols HTTP used for staging, shell control, and callbacks
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
54 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware family reportedly involved in attacks exploiting Apache Tomcat CVE-2026-34486 by a Chinese threat actor.
Dropper used by the threat group to access or support its own infrastructure.
A stager used as follow-on tooling in the WP-SHELLSTORM campaign, associated with payload delivery after initial webshell compromise.
A dropper used to install VShell for persistent remote access on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.