Trellix reported a Linux malware campaign that delivers VShell through a spam email carrying a RAR archive whose malicious logic is embedded in a crafted filename rather than the file's contents. The attack is triggered when unsafe shell scripting patterns interpret that filename through expansion and commands such as eval, echo, printf, or logging routines, causing a Base64-decoded Bash downloader to run. The downloader fingerprints the victim's CPU architecture, retrieves an ELF loader from 47.98.194.60, and attempts stealthy execution with nohup from writable directories.
The ELF loader then contacts a hardcoded command-and-control server, receives an XOR-encrypted payload using key 0x99, decrypts it in memory, and launches the final malware with fexecve() while disguising itself as a kernel worker thread such as [kworker/0:2]. Trellix said the initial stage aligns with Snowlight dropper activity and identified the final payload as VShell, a Go-based Linux backdoor linked primarily to Chinese APT operations. The infection chain is notable for remaining effectively fileless after download, supporting multiple CPU architectures, and evading defenses that do not inspect filenames or in-memory execution behavior.
Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Trellix published research describing a Linux malware chain in which a spam-delivered RAR archive abuses malicious payloads encoded in filenames to trigger shell execution via unsafe scripting patterns. The report linked the initial stage to Snowlight-like activity and identified the final in-memory payload as the Go-based VShell backdoor associated primarily with Chinese APT usage.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.