Last seven days
- First activity
- Aug 14, 2026
- Last activity
- Aug 14, 2026
- Feed role
- C2
- Host form
- 1 IP / 1 hostnames
SNOWLIGHT is a Linux-focused stager and dropper used to deliver the VShell backdoor and related follow-on payloads during post-exploitation.
Profile source: Mallory opens in a new tabSNOWLIGHT
SNOWLIGHT is a Linux-focused stager and dropper used to deliver the VShell backdoor and related follow-on payloads during post-exploitation. It has been observed in intrusion chains associated with multiple China-nexus or Chinese-speaking threat clusters, including UNC5174, UNC6586, UAT-6382, and UAT-8302, and has also appeared in broader mass-exploitation and access-broker activity such as campaigns targeting vulnerable web applications and CMS platforms. Reporting also places it in exploitation of high-profile server-side vulnerabilities including flaws affecting Roundcube, Apache Tomcat, Cityworks, and React/Next.js environments.
The malware’s core role is payload retrieval and execution. Observed variants detect the victim CPU architecture, retrieve a matching ELF implant from command-and-control infrastructure, and execute it in memory or with minimal disk footprint. Multiple reports describe SNOWLIGHT as memory-based or fileless after download, with the final payload commonly being VShell. Execution tradecraft includes use of nohup-style background launching, writable-directory fallback logic, anti-reinfection markers, and process masquerading to resemble Linux kernel worker threads. Some samples decrypt or unpack the next stage in memory and invoke it directly, reducing forensic visibility.
SNOWLIGHT has also been linked to a distinctive filename-abuse execution technique on Linux, where malicious shell payloads are embedded in crafted filenames and triggered by unsafe shell scripting or automated file-handling routines. In other campaigns, it has been launched by shell scripts as a fallback when webshell deployment failed, or used after exploitation of internet-facing applications to establish durable remote access through VShell.
Operationally, SNOWLIGHT is best understood as a reusable loader within a broader tooling ecosystem rather than a standalone access platform. It supports post-compromise persistence of attacker access by installing a backdoor, aids defense evasion through in-memory execution and masquerading, and has been used in both espionage-linked and financially motivated intrusions. Confirmed targeting contexts include Linux servers, cloud and containerized environments, exposed web infrastructure, and compromised operator-controlled VPS systems used to stage implants.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
Both firms linked these activities to UNC5174 through the use of the in-memory backdoor VShell dropped by a downloader named SNOWLIGHT by GTIG.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
Exploited software
MITRE ATT&CK
Reporting
CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog after warning they are being actively exploited: CVE-2026-9198 in IBM Langflow OSS, CVE-2026-34486 in Apache Tomcat, and CVE-2026-18556 in N-able N-central. The Langflow issue is a critical code-injection flaw that can lead to unauthenticated remote code execution on default deployments, while the N-central bug is an authentication bypass vulnerability that N-able said was exploited as a zero-day. CISA also noted exploitation of CVE-2026-18577, a separate N-central flaw tied to an incomplete fix for the original issue. The Apache Tomcat vulnerability allows attackers to bypass EncryptInterceptor protections for cluster-node messages, potentially exposing cluster members to unauthenticated remote code execution. Reporting linked exploitation of the Tomcat flaw to a Chinese-speaking threat actor tracked as knaithe or KnYuan, with activity involving Snowlight malware and AI-enabled autonomous hacking using DeepSeek through the Hermes Agent framework. Under BOD 26-04, Federal Civilian Executive Branch agencies were ordered to remediate the KEV-listed flaws by August 7, and vendors have issued patches including Langflow version 1.10.1 and N-able updates for affected N-central deployments.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.