Last seven days
- First activity
- Jul 23, 2026
- Last activity
- Jul 30, 2026
- Feed role
- C2
- Host form
- 66 IP / 0 hostnames
VShell is a Go-based backdoor used for remote access and post-compromise control on Windows and Linux systems.
Profile source: Mallory opens in a new tabVShell
VShell is a Go-based backdoor used for remote access and post-compromise control on Windows and Linux systems. It has been observed in intrusions involving web server exploitation, compromised mail servers, targeted attacks on MS-SQL environments, and large-scale web exploitation operations. Reported capabilities include interactive shell access, remote command execution, file management, and port forwarding, making it suitable for hands-on-keyboard post-exploitation and covert access to internal services.
VShell has been associated with multiple Chinese-speaking threat ecosystems, including both espionage-oriented and financially motivated operations, but its presence alone is not sufficient for attribution because it is also described as a commodity tool used across different clusters. It has been observed alongside tooling such as SNOWLIGHT, ShadowPad-related infrastructure, webshells, and reconnaissance frameworks. In some campaigns, VShell was delivered by a dropper or shell script and launched directly in memory; in others it was installed after exploitation of internet-facing applications such as Roundcube or after compromise of CMS and server infrastructure.
Documented tradecraft includes process masquerading on Linux by renaming itself to resemble a kernel worker thread in order to evade casual inspection. Communications and transport support reported for VShell include TCP, HTTP, and UDP. It has also been described as supporting plugins or auxiliary tooling for credential access, scanning, tunneling, and account creation in some operator workflows. Across observed incidents, VShell primarily functions as a stealthy persistence and remote administration implant used after initial access has already been obtained.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
the attacker installed VShell and GotoHTTP to gain control over the infected system
В противном случае малварь загружает шелл-скрипт, который запускает прямо в памяти VShell — написанный на Go бэкдор, поддерживающий открытие интерактивного шелла и проброс портов.
For its own remote access, the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list.
Talos has so far found two types of payloads deployed by TetraLoader on the infected endpoints: ... VShell stager ... The payload received by the VShell stager is in fact the actual VShell implant. VShell is a GoLang-based implant that talks to its C2 and provides a wide variety of remote access trojan-based functionalities.
The group deploys NetDraft, a .NET-based backdoor linked to the FinDraft and SquidDoor family, alongside an updated version of the CloudSorcerer backdoor and the VSHELL implant.
SNOWLIGHT, a VShell stager... The attack chains culminate in the deployment of NetDraft, CloudSorcerer (version 3.0), and VShell.
VELETRIX carries a VShell shellcode which is an Offensive Security Tool, like Meterpreter, Cobalt Strike among others, which means that, when executed, it will communicate with the Command and Control server.
China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors
China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors
After gaining access, the operators deployed SnakeC2, NEOBEACON (which abuses OneDrive and the Microsoft Graph API for C2), Cobalt Strike, VShell, and SoftEther VPN.
After gaining access, the operators deployed SnakeC2, NEOBEACON (which abuses OneDrive and the Microsoft Graph API for C2), Cobalt Strike, VShell, and SoftEther VPN.
"The malware used in the campaign included ValleyRAT and VShell."
"CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments."
Among the tools put to use by the threat actor are command-and-control (C2) frameworks... VShell
Exploited software
MITRE ATT&CK
Reporting
A targeted attack on an MS-SQL server led to the deployment of XMRig CoinMiner along with multiple remote-access tools, according to AhnLab ASEC. The intrusion was attributed to the Larva-26009 threat actor, which went beyond the common pattern of opportunistic cryptomining on exposed SQL servers by also installing VShell, GotoHTTP, and SoftEther VPN to maintain control over the compromised system. The toolset indicates the attackers sought both monetization and persistent remote administration after the initial compromise. While coin miners are frequently observed in attacks against internet-exposed Microsoft SQL Server instances, the addition of tunneling and remote-management software suggests a more deliberate post-compromise operation designed to preserve access and expand attacker control over the victim environment.
Researchers reported an active espionage intrusion targeting Thailand’s Ministry of Finance, tied to exposed attacker infrastructure at 43.246.208[.]207 and additional linked hosts in Hong Kong and Malaysia. The operation used the open-source Hermes autonomous AI agent in unattended "YOLO" mode to enumerate ministry systems, map internal services, and assess privilege-escalation paths, while a previously undocumented cross-platform Go implant dubbed Hades was staged to maintain persistence on both Windows and Linux systems. Investigators also linked a VShell C2 server and the domain redhatupdating432.dnsrd.com to the activity. Recovered artifacts showed targeting of ministry administrative panels, mail infrastructure, Apache Hadoop and HiveServer2 environments, Apache Ambari, GlassFish, Alfresco, and internal document systems. The exposed directories contained exploit code, web shells, stolen credentials, credential-testing scripts, and Linux and IIS exploitation or privilege-escalation modules, while Hades reportedly supported command and control, file transfer, proxying, and screen capture. Investigators said the evidence indicates compromised internal access, though no data exfiltration had been confirmed at publication time, and assessed with low-to-moderate confidence that the operator was a Chinese-speaking or Sinophone threat actor based on infrastructure history, Chinese-language indicators, and use of FOFA.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.