Last seven days
- First activity
- Sep 22, 2026
- Last activity
- Sep 28, 2026
- Feed role
- C2 / Distribution
- Host form
- 20 IP / 1 hostnames
SNOWLIGHT is a cross-platform, architecture-aware loader and stager primarily used to retrieve and launch the VShell remote-access backdoor.
Profile source: Mallory opens in a new tabSNOWLIGHT
SNOWLIGHT is a cross-platform, architecture-aware loader and stager primarily used to retrieve and launch the VShell remote-access backdoor. Windows and Linux variants contact command-and-control infrastructure, transmit a short host check-in, retrieve an encrypted payload, decode it in memory, and transfer execution to VShell. Linux variants have selected payloads for x86, x86-64, ARM, and ARM64 systems and can execute decrypted payloads from anonymous in-memory file descriptors. Observed variants use anti-reinfection markers, process-name masquerading resembling Linux kernel worker threads, encrypted or XOR-obfuscated payload delivery, and anti-analysis checks. SNOWLIGHT has appeared in phishing-led Windows intrusions, exploit-driven compromises of internet-facing applications, and a Linux chain in which a malicious archive filename is interpreted by unsafe shell scripting. It has been used by or associated with UNC5174, UNC6586, UAT-6382, and UAT-8302, but its presence alone is insufficient to attribute an intrusion to a particular actor. Activity involving SNOWLIGHT has targeted academic researchers, government entities, and internet-facing enterprise and web infrastructure.
C2 tracking
Derp observations, rolling seven-day window
Samples
36fff810e4fb7de1f052330915dcb2b96413b83fd962cdd021c97537d06c75c2 4bc4987862318f1e1772155e85b0e32c1c9cb90afeefb4d04f3b58d1b51473d6 4eff95566912a2032bc6aff7f0a830ca29f18d815068cfe4bd6240d0fb7b117e 9c1a4318df911281fd7b6971c7fd0e022ebe310b7c49381c6b89ef23ad9551e6 b87c5c316e18095207279dfa929f5f7da5430072902792d54d00158e05616dcd 14d996fb3575d574b60f8a8f5aa97dcf0648b97913c5caad1583e8666e1e1a19 68673e9d58639c1973f74f680a4c18c95c44c102a4308390398e933e5b6b653b 8d3c99aac433d26cd85c0c00efae5d39107f8bf301290c565c8c0a9d1a837b09 b3c275aa8aa13999b14a3af18d970b7f20d0144dd5cf4bd94912de6aa83b1566 dbca105bd59db42253fd02f350563514146ff626c80f3dcd72dc76babfd40f26 Reported operators
The malware suite evaluated in this section has been definitively identified as SNOWLIGHT. This threat toolkit includes a shell dropper alongside four architecture-specific ELF loaders.
The malware suite evaluated in this section has been definitively identified as SNOWLIGHT. This threat toolkit includes a shell dropper alongside four architecture-specific ELF loaders.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
Exploited software
MITRE ATT&CK
Reporting
CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog after warning they are being actively exploited: CVE-2026-9198 in IBM Langflow OSS, CVE-2026-34486 in Apache Tomcat, and CVE-2026-18556 in N-able N-central. The Langflow issue is a critical code-injection flaw that can lead to unauthenticated remote code execution on default deployments, while the N-central bug is an authentication bypass vulnerability that N-able said was exploited as a zero-day. CISA also noted exploitation of CVE-2026-18577, a separate N-central flaw tied to an incomplete fix for the original issue. The Apache Tomcat vulnerability allows attackers to bypass EncryptInterceptor protections for cluster-node messages, potentially exposing cluster members to unauthenticated remote code execution. Reporting linked exploitation of the Tomcat flaw to a Chinese-speaking threat actor tracked as knaithe or KnYuan, with activity involving Snowlight malware and AI-enabled autonomous hacking using DeepSeek through the Hermes Agent framework. Under BOD 26-04, Federal Civilian Executive Branch agencies were ordered to remediate the KEV-listed flaws by August 7, and vendors have issued patches including Langflow version 1.10.1 and N-able updates for affected N-central deployments.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.