SuperShell is an open-source, Go-based command-and-control framework and backdoor that provides reverse-shell access and remote command execution on compromised hosts. It supports Linux, Windows, and Android, and has been repeatedly observed targeting Linux SSH servers. Operators commonly obtain access through SSH dictionary or brute-force attacks against weak credentials, then download and execute SuperShell using common command-line transfer utilities. Deployments have also been observed alongside XMRig cryptocurrency-mining software.
SuperShell has been used following exploitation of internet-facing applications and appliances, including in campaigns exploiting Gogs instances. Its web-based botnet and command-and-control panels have distinctive reusable interface artifacts. The framework is associated with Chinese-speaking operators and has appeared in activity attributed with moderate confidence to the PRC-linked access operator UNC5174, but its availability and use by multiple China-linked threat clusters mean SuperShell alone is not sufficient for actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On April 24, 2025, SAP disclosed CVE-2025-31324, a critical vulnerability with a CVSS score of 10.0 affecting the SAP NetWeaver's Visual Composer Framework, version 7.50. This vulnerability allows unauthenticated users to upload arbitrary files to an SAP NetWeaver application server, leading to potential remote code execution (RCE) and full system compromise. | The IP address 47.97.42[.]177 has also been associated with malware based on the open-source tool SUPERSHELL.
A vulnerability in self-hosted Git service Gogs is facing widespread exploitation, and no patch is available at this time. That's according to Wiz, which on Dec. 10 published research disclosing CVE-2025-8110, a bypass for a remote code execution vulnerability disclosed for Gogs last year (CVE-2024-55947).
Mandiant observed novel N-day exploitation of CVE-2023-46747 affecting F5 BIG-IP Traffic Management User Interface... UNC5174 has been observed attempting to sell access... following CVE-2023-46747 exploitation.
"This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174."
In February 2024, we observed exploitation of Connectwise ScreenConnect CVE-2024-1709 by the same actor... to compromise hundreds of institutions primarily in the U.S. and Canada.
"This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174."
"This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174."
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the threat actor has offered insights into their evolving offensive toolkit, including open-source C2 frameworks like antnium, GateSentinel, and SuperShell
Forescout Vedere Labs linked some of the ongoing attacks to a suspected Chinese threat actor they track as Chaya_004. The threat actor uses malicious infrastructure that includes "a network of servers hosting Supershell backdoors..."
"This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174."
22 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Mapping ... Resource Development Acquire Infrastructure: Virtual Private Server T1583.003 Alibaba Cloud VPS
Qakbot Command and Control Servers ... Qakbot server typically on port 443,993 or 995 ... Same ja3s across malicious servers.
MITRE ATT&CK Mapping ... Command and Control Application Layer Protocol: Web Protocols T1071.001 HTTP-based C2 panel
We observed attackers deploying other reverse shell tools... GOREVERSE has the following capabilities: ... Dynamic, local and remote forwarding ... Multiple network transports... We observed an attacker execute ... a Base64-encoded PowerShell script... Uses ssh.exe to establish a remote tunnel to the C2 server.
MITRE ATT&CK Mapping ... Command and Control Proxy: Multi-hop Proxy T1090.003 RSSH reverse tunnel over WebSocket
Infrastructure analysis also identified artifacts associated with the Metasploit and SuperShell C2 frameworks on the same server. This suggests the operator may leverage these frameworks to generate shellcode payloads delivered through PATCHCORD's in-memory execution capability.
1,578 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chinese-language command-and-control framework found on the exposed staging server as part of the operator toolkit.
An open-source command-and-control framework present in the threat actor's toolkit.
An open-source webshell management and C2 platform providing remote command execution, file management, and reverse shell capabilities. It was found on the staging server as part of the operator toolkit.
The hosting ASN used by CRPX0 infrastructure is described as having also been abused by threat actors spreading Supershell.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.