Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 9, 2026
- Feed role
- C2 / Distribution
- Host form
- 38 IP / 1 hostnames
SNOWLIGHT is a cross-platform, architecture-aware loader and stager primarily used to retrieve and launch the VShell remote-access backdoor.
Profile source: Mallory opens in a new tabSNOWLIGHT
SNOWLIGHT is a cross-platform, architecture-aware loader and stager primarily used to retrieve and launch the VShell remote-access backdoor. Windows and Linux variants contact command-and-control infrastructure, transmit a short host check-in, retrieve an encrypted payload, decode it in memory, and transfer execution to VShell. Linux variants have selected payloads for x86, x86-64, ARM, and ARM64 systems and can execute decrypted payloads from anonymous in-memory file descriptors. Observed variants use anti-reinfection markers, process-name masquerading resembling Linux kernel worker threads, encrypted or XOR-obfuscated payload delivery, and anti-analysis checks. SNOWLIGHT has appeared in phishing-led Windows intrusions, exploit-driven compromises of internet-facing applications, and a Linux chain in which a malicious archive filename is interpreted by unsafe shell scripting. It has been used by or associated with UNC5174, UNC6586, UAT-6382, and UAT-8302, but its presence alone is insufficient to attribute an intrusion to a particular actor. Activity involving SNOWLIGHT has targeted academic researchers, government entities, and internet-facing enterprise and web infrastructure.
C2 tracking
Derp observations, rolling seven-day window
Samples
a3940db32bd7af999c62effe75e134f93633996ef46bdc3f6b249c0c5ac2ea3b b9533ce8e428f16f3d0e1946f19a6f756ff11a532d0b7e61ae402837f46c678e 18e0bf2302dc16191448affb4cfd9584177826a789481a76997037833d905a00 80c881c47e9b7a28e79eb25b0005ceff0e17229c4164235d138141cfebf12cb8 b6d489a8dd7df03e22e5e45dcba015057d2f16365fed2af33a2184d5728a5bfd e767dec2973eab5d61c6422e50d11c5e9a8e5cf01a81fe508e10cd4aec215be4 f1687d04df0d3478cafc0536ed9cc12efc65786cc53badecf85d9012f5bf453c 11a6cf0de7a49a72730475c599bce7b112d583d251411a5d77c5a67fcc7e32c2 2d55df8b32e321ec113578b99a5369af99c8cdde1c7c468ba96a4a30914c32d3 5655dc172ac6d133f60c70d0bd5bbb732822273ff0e910648d0f58a2a643204d Reported operators
The malware suite evaluated in this section has been definitively identified as SNOWLIGHT. This threat toolkit includes a shell dropper alongside four architecture-specific ELF loaders.
The malware suite evaluated in this section has been definitively identified as SNOWLIGHT. This threat toolkit includes a shell dropper alongside four architecture-specific ELF loaders.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
SNOWLIGHT, a VShell stager used by UNC5174, UNC6586, and UAT-6382.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
Multiple groups including UNC6600 and UNC6603 are deploying custom backdoors and tunnelers such as MINOCAT, HISONIC, SNOWLIGHT, and ANGRYREBEL.LINUX.
Exploited software
MITRE ATT&CK
Reporting
CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog after warning they are being actively exploited: CVE-2026-9198 in IBM Langflow OSS, CVE-2026-34486 in Apache Tomcat, and CVE-2026-18556 in N-able N-central. The Langflow issue is a critical code-injection flaw that can lead to unauthenticated remote code execution on default deployments, while the N-central bug is an authentication bypass vulnerability that N-able said was exploited as a zero-day. CISA also noted exploitation of CVE-2026-18577, a separate N-central flaw tied to an incomplete fix for the original issue. The Apache Tomcat vulnerability allows attackers to bypass EncryptInterceptor protections for cluster-node messages, potentially exposing cluster members to unauthenticated remote code execution. Reporting linked exploitation of the Tomcat flaw to a Chinese-speaking threat actor tracked as knaithe or KnYuan, with activity involving Snowlight malware and AI-enabled autonomous hacking using DeepSeek through the Hermes Agent framework. Under BOD 26-04, Federal Civilian Executive Branch agencies were ordered to remediate the KEV-listed flaws by August 7, and vendors have issued patches including Langflow version 1.10.1 and N-able updates for affected N-central deployments.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.