Skip to content

SNOWLIGHT

SNOWLIGHT is a cross-platform, architecture-aware loader and stager primarily used to retrieve and launch the VShell remote-access backdoor.

Profile source: Mallory opens in a new tab

SNOWLIGHT

Family profile

SNOWLIGHT is a cross-platform, architecture-aware loader and stager primarily used to retrieve and launch the VShell remote-access backdoor. Windows and Linux variants contact command-and-control infrastructure, transmit a short host check-in, retrieve an encrypted payload, decode it in memory, and transfer execution to VShell. Linux variants have selected payloads for x86, x86-64, ARM, and ARM64 systems and can execute decrypted payloads from anonymous in-memory file descriptors. Observed variants use anti-reinfection markers, process-name masquerading resembling Linux kernel worker threads, encrypted or XOR-obfuscated payload delivery, and anti-analysis checks. SNOWLIGHT has appeared in phishing-led Windows intrusions, exploit-driven compromises of internet-facing applications, and a Linux chain in which a malicious archive filename is interpreted by unsafe shell scripting. It has been used by or associated with UNC5174, UNC6586, UAT-6382, and UAT-8302, but its presence alone is insufficient to attribute an intrusion to a particular actor. Activity involving SNOWLIGHT has targeted academic researchers, government entities, and internet-facing enterprise and web infrastructure.

Capabilities

  • Defense Evasion
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 2, 2026
Last activity
Sep 9, 2026
Feed role
C2 / Distribution
Host form
38 IP / 1 hostnames

Leading locations

  • CN18
  • HK6
  • SG5
  • US4
  • JP2
  • ES1
  • KR1
  • NL1
  • TW1

Leading providers

  • Shenzhen Tencent Computer Systems Company Limited10
  • Hangzhou Alibaba Advertising Co.,Ltd.4
  • Tencent Building, Kejizhongyi Avenue3
  • VH Global Limited2
  • ABCCLOUD SDN.BHD.1
  • Akamai Connected Cloud1

Infrastructure traits

  • Hosting 36

Samples

Recent associated samples

Reported operators

Threat actors

6 named in public reporting
UNC5174

The malware suite evaluated in this section has been definitively identified as SNOWLIGHT. This threat toolkit includes a shell dropper alongside four architecture-specific ELF loaders.

UNC6586

The malware suite evaluated in this section has been definitively identified as SNOWLIGHT. This threat toolkit includes a shell dropper alongside four architecture-specific ELF loaders.

UAT-8302

SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.

UAT-6382

SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.

UNC6603

Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.

UNC6600

Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.

Exploited software

Vulnerabilities linked to SNOWLIGHT

15 CVEs

MITRE ATT&CK

SNOWLIGHT in ATT&CK

30 distinct techniques

Reporting

Research mentioning SNOWLIGHT

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.