Trellix reported a Linux malware campaign that delivers VShell through a spam email carrying a RAR archive whose malicious logic is embedded in a crafted filename rather than the file's contents. The attack is triggered when unsafe shell scripting patterns interpret that filename through expansion and commands such as eval, echo, printf, or logging routines, causing a Base64-decoded Bash downloader to run. The downloader fingerprints the victim's CPU architecture, retrieves an ELF loader from 47.98.194.60, and attempts stealthy execution with nohup from writable directories.
The ELF loader then contacts a hardcoded command-and-control server, receives an XOR-encrypted payload using key 0x99, decrypts it in memory, and launches the final malware with fexecve() while disguising itself as a kernel worker thread such as [kworker/0:2]. Trellix said the initial stage aligns with Snowlight dropper activity and identified the final payload as VShell, a Go-based Linux backdoor linked primarily to Chinese APT operations. The infection chain is notable for remaining effectively fileless after download, supporting multiple CPU architectures, and evading defenses that do not inspect filenames or in-memory execution behavior.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Trellix published research describing a Linux malware chain in which a spam-delivered RAR archive abuses malicious payloads encoded in filenames to trigger shell execution via unsafe scripting patterns. The report linked the initial stage to Snowlight-like activity and identified the final in-memory payload as the Go-based VShell backdoor associated primarily with Chinese APT usage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.