Skip to content

SNOWLIGHT

SNOWLIGHT is a Linux-focused stager and dropper used to deliver the VShell backdoor and related follow-on payloads during post-exploitation.

Profile source: Mallory opens in a new tab

SNOWLIGHT

Family profile

SNOWLIGHT is a Linux-focused stager and dropper used to deliver the VShell backdoor and related follow-on payloads during post-exploitation. It has been observed in intrusion chains associated with multiple China-nexus or Chinese-speaking threat clusters, including UNC5174, UNC6586, UAT-6382, and UAT-8302, and has also appeared in broader mass-exploitation and access-broker activity such as campaigns targeting vulnerable web applications and CMS platforms. Reporting also places it in exploitation of high-profile server-side vulnerabilities including flaws affecting Roundcube, Apache Tomcat, Cityworks, and React/Next.js environments.

The malware’s core role is payload retrieval and execution. Observed variants detect the victim CPU architecture, retrieve a matching ELF implant from command-and-control infrastructure, and execute it in memory or with minimal disk footprint. Multiple reports describe SNOWLIGHT as memory-based or fileless after download, with the final payload commonly being VShell. Execution tradecraft includes use of nohup-style background launching, writable-directory fallback logic, anti-reinfection markers, and process masquerading to resemble Linux kernel worker threads. Some samples decrypt or unpack the next stage in memory and invoke it directly, reducing forensic visibility.

SNOWLIGHT has also been linked to a distinctive filename-abuse execution technique on Linux, where malicious shell payloads are embedded in crafted filenames and triggered by unsafe shell scripting or automated file-handling routines. In other campaigns, it has been launched by shell scripts as a fallback when webshell deployment failed, or used after exploitation of internet-facing applications to establish durable remote access through VShell.

Operationally, SNOWLIGHT is best understood as a reusable loader within a broader tooling ecosystem rather than a standalone access platform. It supports post-compromise persistence of attacker access by installing a backdoor, aids defense evasion through in-memory execution and masquerading, and has been used in both espionage-linked and financially motivated intrusions. Confirmed targeting contexts include Linux servers, cloud and containerized environments, exposed web infrastructure, and compromised operator-controlled VPS systems used to stage implants.

Capabilities

  • Defense Evasion
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 14, 2026
Last activity
Aug 14, 2026
Feed role
C2
Host form
1 IP / 1 hostnames

Leading locations

  • DE1
  • JP1

Leading providers

  • Omegatech LTD1
  • SAKURA Internet Inc.1

Infrastructure traits

  • Hosting 2
  • Proxy 1
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

6 named in public reporting
UNC5174

Both firms linked these activities to UNC5174 through the use of the in-memory backdoor VShell dropped by a downloader named SNOWLIGHT by GTIG.

UNC6586

SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.

UAT-8302

SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.

UAT-6382

SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.

UNC6603

Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.

UNC6600

Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.

Exploited software

Vulnerabilities linked to SNOWLIGHT

15 CVEs

MITRE ATT&CK

SNOWLIGHT in ATT&CK

21 distinct techniques

Reporting

Research mentioning SNOWLIGHT

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.