#vshell
It's such a huge pain to my reversing pride that Go obfuscation kicks my ass so much. I think I have to give up on reversing this VShell sample, I've gotten as far as I could. I need to find more Go samples to practice with.
September 27, 2026 at 2:00 AM
NVISO has linked VShell to UNC5174, a cyber contractor for the Chinese MSS

www.nviso.eu/blog/nviso-a...
November 6, 2025 at 11:15 AM
I've been seeing Vshell in #opendirs for a few years. With the recent attention, it was time to do a proper write-up on it:
https://censys.com/blog/vshell/
February 24, 2026 at 2:50 PM
Be careful all of my Linux using friends! New threat out there...

@scottculkin.bsky.social
Linux Malware Delivered via Malicious RAR Filenames Evades Antivirus Detection
Phishing emails with RAR archives exploit Linux filename injection to deliver VShell backdoor, bypassing antivirus defenses
thehackernews.com
August 25, 2025 at 1:44 AM
China-linked UNC5174 group uses SNOWLIGHT malware and VShell RAT to target Linux and macOS systems. SNOWLIGHT acts as a dropper for VShell, enabling remote access. Attacks leverage open-source tools for obfuscation. Initial access vector remains unknown.#SNOWLIGHTVShellThreat
April 16, 2025 at 2:38 AM
-Modernizing the Acquisition of Cybersecurity Experts Act
-Former employee sentenced to jail for sabotaging employer's network
-Malicious Go module steals creds
-npm malware targets Russian web3 devs
-G*yf*mb*y botnet returns
-VShell targets targets Linux
-New SpyNote tactics mimic Play Store pages
August 25, 2025 at 7:22 AM
Huh, looks like VirusTotal added the support for parsing VShell config. You should be able to now hunt for it with something like malware_config:vshell
November 19, 2024 at 2:00 AM
Security researchers at Sysdig discover threat actors repurposing legitimate open source security tools for cyberattacks, with Chinese-sponsored UNC5174 group leveraging Linux-based VShell and other tools to evade detection.
Linux Security Software Turned Against Users
Security researchers at Sysdig discover threat actors repurposing legitimate open source security tools for cyberattacks, with Chinese-sponsored UNC5174 group leveraging Linux-based VShell and other tools to evade detection.
bit.ly
May 18, 2025 at 5:00 PM
God the VShell crew is constantly updating their Go payload loader. Makes me annoyed since I was so accustomed to their current loader.
September 22, 2026 at 12:30 AM
Vshell gains Traction among Threat Actors as an Alternative to Cobalt Strike:

cybersecuritynews.com/vshell-gains...
March 1, 2026 at 11:56 AM
Seeing a significant uptick in VShell campaigns on MalwareBazaar. I think I see an opportunity to report on this malware family!
September 21, 2026 at 12:16 AM
Vshell: A Chinese-Language Alternative to Cobalt Strike  - Censys censys.com/blog/vshell/
Vshell: A Chinese-Language Alternative to Cobalt Strike  - Censys
Vshell is a Go-based remote administration tool that provides post-compromise capabilities for network pivoting and proxying. While the project is marketed as non-malicious, publicly available…
censys.com
March 19, 2026 at 7:42 AM
Mohair Capelet.

Patterns: Hobbii Daphne Cape, VShell Dress (freehand)
Necklace: @EclecticGlass
Styled by: Sharifa Ali
Pic by: Winding Lake Arts

#windinglakemedia #windinglakearts #crochet #2025 #glassart #fusedglass #capelet
May 19, 2025 at 11:04 PM
SANS Stormcast Thursday, November 6th, 2025: Domain API Update; Teams Spoofing; VShell Report
https://isc.sans.edu/podcastdetail/9688
November 6, 2025 at 3:35 AM
BeyondTrustの深刻な脆弱性(CVE-2026-1731)を悪用したVShellとSparkRATを確認
#CybersecurityNews
unit42.paloaltonetworks.com/beyondtrust-...
VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)
CVE-2026-1731 is an RCE vulnerability in identity platform BeyondTrust. This flaw allows attackers control of systems without login credentials.
unit42.paloaltonetworks.com
February 21, 2026 at 2:05 PM
Chinese Hackers Target Linux Systems Using SNOWLIGHT Malware and VShell Tool

The China-linked threat actor known as UNC5174 has been attributed to a new campaign that leverages a variant of a known malware dubbed SNOWLIGHT and a new open-source tool called VShell to infect Linux…

#hackernews #news
Chinese Hackers Target Linux Systems Using SNOWLIGHT Malware and VShell Tool
The China-linked threat actor known as UNC5174 has been attributed to a new campaign that leverages a variant of a known malware dubbed SNOWLIGHT and a new open-source tool called VShell to infect Linux systems. "Threat actors are increasingly using open source tools in their arsenals for cost-effectiveness and obfuscation to save money and, in this case, plausibly blend in with the pool of
thehackernews.com
April 16, 2025 at 2:13 PM
New Linux Malware With Weaponized RAR Archive Deploys VShell Backdoor
New Linux Malware With Weaponized RAR Archive Deploys VShell Backdoor
cybersecuritynews.com
August 22, 2025 at 9:33 AM
Bösartige Kampagne der APT-Gruppe UNC5174 kombiniert Snowlight und VShell

#Cyberbedrohung #Cybersecurity #Cyberspionage #Linux #Malware #RemoteAccessTrojaner #Snowlight @Sysdig #VShell

netzpalaver.de/2025/...
April 16, 2025 at 2:28 PM
VShell is fucking with me. It loads a position-independent shellcode with Go artifacts that loads from the DOS header that's also a valid PE file. I think it loads its Go runtime in the shellcode loading process. This is fun, but confusing!
September 22, 2026 at 8:11 AM
Chinese Hackers Target Linux Systems Using SNOWLIGHT Malware and VShell Tool
thehackernews.com/2025/04/chin...
Chinese Hackers Target Linux Systems Using SNOWLIGHT Malware and VShell Tool
UNC5174 uses SNOWLIGHT and VShell to target Linux and macOS systems, exploiting Ivanti flaws for remote control.
thehackernews.com
April 16, 2025 at 5:48 AM
UAT-6382, Chinese state-sponsored hackers, exploited patched CVE-2025-0944 in Trimble Cityworks since January 2025, infiltrating US government networks. Malware (Cobalt Strike, VShell, AntSword, Behinder) enabled reconnaissance and data theft.#TrimbleCityworksHack
May 22, 2025 at 6:30 PM