Last seven days
- First activity
- Sep 6, 2026
- Last activity
- Sep 12, 2026
- Feed role
- C2 / Distribution
- Host form
- 65 IP / 3 hostnames
VShell is a Go-based, cross-platform remote-access trojan and backdoor supporting Windows, Linux, and macOS/Darwin systems.
Profile source: Mallory opens in a new tabVShell
VShell is a Go-based, cross-platform remote-access trojan and backdoor supporting Windows, Linux, and macOS/Darwin systems. It provides interactive command execution, file browsing and transfer, screenshot capture, network discovery, and proxy/tunneling functions, including SOCKS5, HTTP, and TCP/UDP proxying for pivoting and data movement. It supports multiple command-and-control transports, including TCP, UDP, WebSockets, DNS, DNS-over-HTTPS, DNS-over-TLS, and object-storage services, and uses encrypted communications.
VShell is commonly deployed after compromise of public-facing systems, including edge appliances and webmail infrastructure, and has also been delivered through spearphishing lures as a later-stage payload. It supports shellcode, stager, and full-beacon payload formats, in-memory execution, plugins, and persistence features. Versions have incorporated anti-sandbox functionality, encrypted traffic, reduced command logging, and eBPF-related support. VShell has been used in long-running espionage, pre-positioning, and access-brokering activity, as well as financially motivated intrusions. It has been associated with UNC5174, Houken, UNK_MassTraction, and other clusters, but its use alone is not sufficient to attribute an intrusion to any one actor. Victims have included government, healthcare, military, research, academic, telecommunications, finance, transport, and technology organizations worldwide.
C2 tracking
Derp observations, rolling seven-day window
Samples
7d260805c9653f49b5b261b9bc22cf1e77d72bc3ac37f4d5463afd54fd1680f8 b36d30ad0a646eeed5f02b48ac6b02f2cd2c125df298252dc1070aeff80de3e3 b639aaf8596969a505f5072bef830045dc2d12d8e1b9595ca7167847f7584428 c56a5e1bd3be186d26a106464ee40c11d9631a806b5fca076781403e1037990e c96c694edcf204a4a517f62bd9969b14e8f504a815a324f6097dcadbc0096f09 11e862accfc3f80899d081ff30d6795d151edc4f5cb7df894f7bec56d51433af a6b9e11dd7457c49ef440964ef625cb34762d94b894e05925f92fc14d1e2b714 b8157a882e669dfd8372888888f56263ce10ae41f371750e3ae9f7f816b76094 d74ee8bb9337b8dd250ce28e0e8607680f83719a28906f6410aa4a6addbd720c 3ebb5316c670fdc6b56a237603d78468d39abdca51acdb4387b5e3562d61d863 Reported operators
UNK_MassTraction repeatedly exploited Roundcube vulnerabilities to infiltrate university networks and used IceCube, SquareShell, and VShell.
Houken operators used open-source tools previously detailed as part of UNC5174 intrusion set such as: GOREVERSE, VShell, fscan or ffuff.
VShell is a full-fledged remote access trojan (RAT), programmed in Go... It has offensive capabilities such as capturing screenshots of victim computers, allows for browsing as well as uploading and downloading files, and the ability to remotely execute commands as a backdoor.
the attacker installed VShell and GotoHTTP to gain control over the infected system
Talos has so far found two types of payloads deployed by TetraLoader on the infected endpoints: ... VShell stager ... The payload received by the VShell stager is in fact the actual VShell implant. VShell is a GoLang-based implant that talks to its C2 and provides a wide variety of remote access trojan-based functionalities.
The group deploys NetDraft, a .NET-based backdoor linked to the FinDraft and SquidDoor family, alongside an updated version of the CloudSorcerer backdoor and the VSHELL implant.
SNOWLIGHT, a VShell stager... The attack chains culminate in the deployment of NetDraft, CloudSorcerer (version 3.0), and VShell.
VELETRIX carries a VShell shellcode which is an Offensive Security Tool, like Meterpreter, Cobalt Strike among others, which means that, when executed, it will communicate with the Command and Control server.
China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors
China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors
After gaining access, the operators deployed SnakeC2, NEOBEACON (which abuses OneDrive and the Microsoft Graph API for C2), Cobalt Strike, VShell, and SoftEther VPN.
After gaining access, the operators deployed SnakeC2, NEOBEACON (which abuses OneDrive and the Microsoft Graph API for C2), Cobalt Strike, VShell, and SoftEther VPN.
"The malware used in the campaign included ValleyRAT and VShell."
"CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments."
Among the tools put to use by the threat actor are command-and-control (C2) frameworks... VShell
Exploited software
MITRE ATT&CK
Reporting
A targeted attack on an MS-SQL server led to the deployment of XMRig CoinMiner along with multiple remote-access tools, according to AhnLab ASEC. The intrusion was attributed to the Larva-26009 threat actor, which went beyond the common pattern of opportunistic cryptomining on exposed SQL servers by also installing VShell, GotoHTTP, and SoftEther VPN to maintain control over the compromised system. The toolset indicates the attackers sought both monetization and persistent remote administration after the initial compromise. While coin miners are frequently observed in attacks against internet-exposed Microsoft SQL Server instances, the addition of tunneling and remote-management software suggests a more deliberate post-compromise operation designed to preserve access and expand attacker control over the victim environment.
Researchers reported an active espionage intrusion targeting Thailand’s Ministry of Finance, tied to exposed attacker infrastructure at 43.246.208[.]207 and additional linked hosts in Hong Kong and Malaysia. The operation used the open-source Hermes autonomous AI agent in unattended "YOLO" mode to enumerate ministry systems, map internal services, and assess privilege-escalation paths, while a previously undocumented cross-platform Go implant dubbed Hades was staged to maintain persistence on both Windows and Linux systems. Investigators also linked a VShell C2 server and the domain redhatupdating432.dnsrd.com to the activity. Recovered artifacts showed targeting of ministry administrative panels, mail infrastructure, Apache Hadoop and HiveServer2 environments, Apache Ambari, GlassFish, Alfresco, and internal document systems. The exposed directories contained exploit code, web shells, stolen credentials, credential-testing scripts, and Linux and IIS exploitation or privilege-escalation modules, while Hades reportedly supported command and control, file transfer, proxying, and screen capture. Investigators said the evidence indicates compromised internal access, though no data exfiltration had been confirmed at publication time, and assessed with low-to-moderate confidence that the operator was a Chinese-speaking or Sinophone threat actor based on infrastructure history, Chinese-language indicators, and use of FOFA.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.