SuperShell is a Go-based backdoor and command-and-control framework associated primarily with Chinese-speaking operators and repeatedly observed in campaigns linked to China-nexus threat activity. It is used as a reverse shell and remote access capability, enabling attackers to execute commands on compromised systems and maintain post-compromise control. Reporting also describes it as an open-source Chinese-language C2 framework that has appeared both as attacker tooling on staging servers and as an active implant deployed on victim systems.
SuperShell has been observed targeting Linux SSH servers through brute-force and dictionary attacks against weak credentials, after which operators download and execute the payload using common command-line transfer utilities. It supports cross-platform operation, with documented support for Linux, Windows, and Android. In Linux intrusions it has also been deployed alongside XMRig, indicating mixed objectives that can include persistent access and cryptomining.
The malware has been tied to exploitation-driven intrusion chains as well. It has been observed in activity exploiting public-facing applications and appliances, including campaigns involving ConnectWise ScreenConnect, F5 BIG-IP, SAP NetWeaver, and Gogs. In some cases, SuperShell functioned as follow-on payloading after successful exploitation; in others, exposed attacker infrastructure contained SuperShell as part of a broader toolkit alongside RAT frameworks, credential-harvesting tools, brute-force tooling, and exploit code.
SuperShell is associated in multiple investigations with PRC-linked or China-nexus actors, including UNC5174 and other clusters tracked by vendors as Chinese-speaking operators. It has also appeared in infrastructure overlaps involving broader China-nexus ecosystems and operational relay infrastructure. Victim sectors and environments linked to SuperShell-related activity include telecommunications, government, defense, research and education, critical infrastructure, and internet-exposed server environments. Its recurring role is to provide durable remote access and operator control after initial compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On April 24, 2025, SAP disclosed CVE-2025-31324, a critical vulnerability with a CVSS score of 10.0 affecting the SAP NetWeaver's Visual Composer Framework, version 7.50. This vulnerability allows unauthenticated users to upload arbitrary files to an SAP NetWeaver application server, leading to potential remote code execution (RCE) and full system compromise. | The IP address 47.97.42[.]177 has also been associated with malware based on the open-source tool SUPERSHELL.
A vulnerability in self-hosted Git service Gogs is facing widespread exploitation, and no patch is available at this time. That's according to Wiz, which on Dec. 10 published research disclosing CVE-2025-8110, a bypass for a remote code execution vulnerability disclosed for Gogs last year (CVE-2024-55947).
Mandiant observed novel N-day exploitation of CVE-2023-46747 affecting F5 BIG-IP Traffic Management User Interface... UNC5174 has been observed attempting to sell access... following CVE-2023-46747 exploitation.
"This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174."
In February 2024, we observed exploitation of Connectwise ScreenConnect CVE-2024-1709 by the same actor... to compromise hundreds of institutions primarily in the U.S. and Canada.
"This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174."
"This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174."
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Forescout Vedere Labs linked some of the ongoing attacks to a suspected Chinese threat actor they track as Chaya_004. The threat actor uses malicious infrastructure that includes "a network of servers hosting Supershell backdoors..."
"This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174."
22 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Mapping ... Resource Development Acquire Infrastructure: Virtual Private Server T1583.003 Alibaba Cloud VPS
Qakbot Command and Control Servers ... Qakbot server typically on port 443,993 or 995 ... Same ja3s across malicious servers.
MITRE ATT&CK Mapping ... Command and Control Application Layer Protocol: Web Protocols T1071.001 HTTP-based C2 panel
We observed attackers deploying other reverse shell tools... GOREVERSE has the following capabilities: ... Dynamic, local and remote forwarding ... Multiple network transports... We observed an attacker execute ... a Base64-encoded PowerShell script... Uses ssh.exe to establish a remote tunnel to the C2 server.
MITRE ATT&CK Mapping ... Command and Control Proxy: Multi-hop Proxy T1090.003 RSSH reverse tunnel over WebSocket
Infrastructure analysis also identified artifacts associated with the Metasploit and SuperShell C2 frameworks on the same server. This suggests the operator may leverage these frameworks to generate shellcode payloads delivered through PATCHCORD's in-memory execution capability.
1,568 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chinese-language command-and-control framework found on the exposed staging server as part of the operator toolkit.
An open-source webshell management and C2 platform providing remote command execution, file management, and reverse shell capabilities. It was found on the staging server as part of the operator toolkit.
Command-and-control framework observed on the same subnet as multiple malware families.
Golang-based malicious web shell/backdoor deployed after exploiting SAP NetWeaver RCE (CVE-2025-31324).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.