Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 19, 2026
- Feed role
- C2
- Host form
- 42 IP / 0 hostnames
VShell is a publicly available Go-based backdoor and remote access implant used in intrusions across Linux, Windows, and macOS environments.
Profile source: Mallory opens in a new tabVShell
VShell is a publicly available Go-based backdoor and remote access implant used in intrusions across Linux, Windows, and macOS environments. It is commonly described as a fully featured remote administration implant and has been repeatedly observed in operations linked to Chinese-speaking and China-aligned threat actors, although its availability and use in criminal ecosystems mean its presence alone is not sufficient for attribution.
VShell provides post-compromise remote access capabilities including interactive shell access, arbitrary command execution, file operations, port forwarding, screenshot capture, and proxying functionality. Multiple reports describe it as supporting broad remote administration and post-exploitation control on compromised systems, especially internet-facing servers. In several observed Linux deployments, VShell was executed directly in memory and paired with process masquerading to reduce visibility, including renaming itself to resemble a kernel worker thread. It has also been delivered through stagers and custom loaders that decrypt or decode the implant in memory before execution.
Observed delivery chains show VShell used as a follow-on payload after exploitation rather than as a primary initial-access mechanism. It has been deployed after exploitation of public-facing applications including Roundcube, Trimble Cityworks, BeyondTrust Remote Support, and mass exploitation of vulnerable WordPress and other CMS components. In these campaigns, operators used webshells, shell scripts, Rust-based loaders, or ELF droppers such as SNOWLIGHT and TetraLoader to install or inject VShell. Some campaigns used it as a fallback persistence and remote-access option when webshell deployment failed.
Victimology associated with VShell spans universities, government and public-sector networks, financial services, healthcare, legal services, technology organizations, utilities-related environments, and broadly exposed web infrastructure. It has appeared in espionage-oriented campaigns targeting research institutions and public-sector entities as well as financially motivated mass-exploitation and access-brokerage operations. The malware’s cross-platform support, in-memory execution patterns, and compatibility with broader Chinese-speaking offensive tooling ecosystems have made it a recurring implant in both targeted and opportunistic intrusions.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
В противном случае малварь загружает шелл-скрипт, который запускает прямо в памяти VShell — написанный на Go бэкдор, поддерживающий открытие интерактивного шелла и проброс портов.
For its own remote access, the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list.
Talos has so far found two types of payloads deployed by TetraLoader on the infected endpoints: ... VShell stager ... The payload received by the VShell stager is in fact the actual VShell implant. VShell is a GoLang-based implant that talks to its C2 and provides a wide variety of remote access trojan-based functionalities.
The group deploys NetDraft, a .NET-based backdoor linked to the FinDraft and SquidDoor family, alongside an updated version of the CloudSorcerer backdoor and the VSHELL implant.
SNOWLIGHT, a VShell stager... The attack chains culminate in the deployment of NetDraft, CloudSorcerer (version 3.0), and VShell.
VELETRIX carries a VShell shellcode which is an Offensive Security Tool, like Meterpreter, Cobalt Strike among others, which means that, when executed, it will communicate with the Command and Control server.
China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors
China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors
After gaining access, the operators deployed SnakeC2, NEOBEACON (which abuses OneDrive and the Microsoft Graph API for C2), Cobalt Strike, VShell, and SoftEther VPN.
After gaining access, the operators deployed SnakeC2, NEOBEACON (which abuses OneDrive and the Microsoft Graph API for C2), Cobalt Strike, VShell, and SoftEther VPN.
"The malware used in the campaign included ValleyRAT and VShell."
"CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments."
Among the tools put to use by the threat actor are command-and-control (C2) frameworks... VShell
Exploited software
MITRE ATT&CK
Reporting
The primary collection node 112.213.124[.]132 hosted a multi-tiered offensive toolkit featuring the ARL (Attack Reconnaissance Lighthouse) framework for network mapping, DeepAudit for vulnerability identification, and Vshell for remote system administration.
В противном случае малварь загружает шелл-скрипт, который запускает прямо в памяти VShell — написанный на Go бэкдор, поддерживающий открытие интерактивного шелла и проброс портов.
VSHell6
Observed duration 22 days for the exposed campaign window Notable follow-on tooling SNOWLIGHT stager and VShell implant with process masquerading
For its own remote access, the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list.
The attackers then use a deserialization exploit, CVE-2025-49113, to install a webshell called SquareShell and a VShell implant, enabling remote code execution.
The implant itself, identified as VShell, takes deliberate steps to avoid detection: once running, it renames its own process to “[kworker/0:2]”...
Successful attacks steal credentials, install webshells, or deploy memory-resident VShell backdoors.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.