Skip to content

VShell

VShell is a Go-based backdoor used for remote access and post-compromise control on Windows and Linux systems.

Profile source: Mallory opens in a new tab

VShell

Family profile

VShell is a Go-based backdoor used for remote access and post-compromise control on Windows and Linux systems. It has been observed in intrusions involving web server exploitation, compromised mail servers, targeted attacks on MS-SQL environments, and large-scale web exploitation operations. Reported capabilities include interactive shell access, remote command execution, file management, and port forwarding, making it suitable for hands-on-keyboard post-exploitation and covert access to internal services.

VShell has been associated with multiple Chinese-speaking threat ecosystems, including both espionage-oriented and financially motivated operations, but its presence alone is not sufficient for attribution because it is also described as a commodity tool used across different clusters. It has been observed alongside tooling such as SNOWLIGHT, ShadowPad-related infrastructure, webshells, and reconnaissance frameworks. In some campaigns, VShell was delivered by a dropper or shell script and launched directly in memory; in others it was installed after exploitation of internet-facing applications such as Roundcube or after compromise of CMS and server infrastructure.

Documented tradecraft includes process masquerading on Linux by renaming itself to resemble a kernel worker thread in order to evade casual inspection. Communications and transport support reported for VShell include TCP, HTTP, and UDP. It has also been described as supporting plugins or auxiliary tooling for credential access, scanning, tunneling, and account creation in some operator workflows. Across observed incidents, VShell primarily functions as a stealthy persistence and remote administration implant used after initial access has already been obtained.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 23, 2026
Last activity
Jul 30, 2026
Feed role
C2
Host form
66 IP / 0 hostnames

Leading locations

  • CN32
  • HK13
  • SG8
  • US7
  • JP3
  • BR1
  • RO1
  • VN1

Leading providers

  • Shenzhen Tencent Computer Systems Company Limited17
  • Hangzhou Alibaba Advertising Co.,Ltd.7
  • HostPapa4
  • Kaopu Cloud HK Limited3
  • SonderCloud Limited3
  • Tcloudnet3

Infrastructure traits

  • Hosting 60
  • Vpn 3

Reported operators

Threat actors

14 named in public reporting
Larva-26009

the attacker installed VShell and GotoHTTP to gain control over the infected system

UNK_MassTraction

В противном случае малварь загружает шелл-скрипт, который запускает прямо в памяти VShell — написанный на Go бэкдор, поддерживающий открытие интерактивного шелла и проброс портов.

UNC5174

For its own remote access, the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list.

UAT-6382

Talos has so far found two types of payloads deployed by TetraLoader on the infected endpoints: ... VShell stager ... The payload received by the VShell stager is in fact the actual VShell implant. VShell is a GoLang-based implant that talks to its C2 and provides a wide variety of remote access trojan-based functionalities.

UAT-8302

The group deploys NetDraft, a .NET-based backdoor linked to the FinDraft and SquidDoor family, alongside an updated version of the CloudSorcerer backdoor and the VSHELL implant.

UNC6586

SNOWLIGHT, a VShell stager... The attack chains culminate in the deployment of NetDraft, CloudSorcerer (version 3.0), and VShell.

Earth Alux

VELETRIX carries a VShell shellcode which is an Offensive Security Tool, like Meterpreter, Cobalt Strike among others, which means that, when executed, it will communicate with the Command and Control server.

Earth Lamia

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Jackpot Panda

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Earth Krahang

After gaining access, the operators deployed SnakeC2, NEOBEACON (which abuses OneDrive and the Microsoft Graph API for C2), Cobalt Strike, VShell, and SoftEther VPN.

APT41

After gaining access, the operators deployed SnakeC2, NEOBEACON (which abuses OneDrive and the Microsoft Graph API for C2), Cobalt Strike, VShell, and SoftEther VPN.

Silver Fox

"The malware used in the campaign included ValleyRAT and VShell."

HAFNIUM

"CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments."

TGR-STA-1030

Among the tools put to use by the threat actor are command-and-control (C2) frameworks... VShell

Exploited software

Vulnerabilities linked to VShell

20 CVEs
CVE-2025-49113 Authenticated RCE in Roundcube Webmail upload.php via PHP Object Deserialization CVE-2020-25213 Unauthenticated Arbitrary File Upload and RCE in WordPress File Manager CVE-2025-34085 Rejected duplicate of CVE-2020-36847 in WordPress Simple File List CVE-2026-0740 Unauthenticated Arbitrary File Upload in Ninja Forms - File Uploads for WordPress CVE-2026-3844 Unauthenticated Arbitrary File Upload in Breeze Cache for WordPress CVE-2026-6433 SQL injection to PHP code execution in Custom CSS JS PHP WordPress plugin CVE-2026-1969 Arbitrary File Upload in ThemeREX Addons for WordPress CVE-2026-48907 Unauthenticated RCE in Joomla JCE Profile Import CVE-2025-12057 Arbitrary File Upload in WavePlayer WordPress Plugin CVE-2025-7852 Arbitrary File Upload in WPBookit WordPress Plugin CVE-2025-7443 Arbitrary File Upload in BerqWP WordPress Plugin CVE-2024-42009 Stored XSS in Roundcube message_body() CVE-2023-2868 Barracuda Email Security Gateway .tar Filename Command Injection CVE-2025-0994 Remote Code Execution in Trimble Cityworks Deserialization CVE-2025-0944 SQL Injection in itsourcecode Tailoring Management System 1.0 customerview.php CVE-2026-1731 Pre-auth OS Command Injection RCE in BeyondTrust Remote Support and Privileged Remote Access CVE-2025-55182 React2Shell CVE-2025-42999 Insecure Deserialization in SAP NetWeaver Visual Composer Metadata Uploader CVE-2024-23897 Jenkins CLI Arbitrary File Read CVE-2025-31324 Unauthenticated Arbitrary File Upload and RCE in SAP NetWeaver Visual Composer Metadata Uploader

MITRE ATT&CK

VShell in ATT&CK

39 distinct techniques

Reporting

Research mentioning VShell

Jul 29
Malware News

Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN - Malware Analysis - Malware Analysis, News and Indicators

A targeted attack on an MS-SQL server led to the deployment of XMRig CoinMiner along with multiple remote-access tools, according to AhnLab ASEC. The intrusion was attributed to the Larva-26009 threat actor, which went beyond the common pattern of opportunistic cryptomining on exposed SQL servers by also installing VShell, GotoHTTP, and SoftEther VPN to maintain control over the compromised system. The toolset indicates the attackers sought both monetization and persistent remote administration after the initial compromise. While coin miners are frequently observed in attacks against internet-exposed Microsoft SQL Server instances, the addition of tunneling and remote-management software suggests a more deliberate post-compromise operation designed to preserve access and expand attacker control over the victim environment.

Jul 24
Scworld

AI assistant used in cyberattack on Thailand's Ministry of Finance | brief | SC Media

Researchers reported an active espionage intrusion targeting Thailand’s Ministry of Finance, tied to exposed attacker infrastructure at 43.246.208[.]207 and additional linked hosts in Hong Kong and Malaysia. The operation used the open-source Hermes autonomous AI agent in unattended "YOLO" mode to enumerate ministry systems, map internal services, and assess privilege-escalation paths, while a previously undocumented cross-platform Go implant dubbed Hades was staged to maintain persistence on both Windows and Linux systems. Investigators also linked a VShell C2 server and the domain redhatupdating432.dnsrd.com to the activity. Recovered artifacts showed targeting of ministry administrative panels, mail infrastructure, Apache Hadoop and HiveServer2 environments, Apache Ambari, GlassFish, Alfresco, and internal document systems. The exposed directories contained exploit code, web shells, stolen credentials, credential-testing scripts, and Linux and IIS exploitation or privilege-escalation modules, while Hades reportedly supported command and control, file transfer, proxying, and screen capture. Investigators said the evidence indicates compromised internal access, though no data exfiltration had been confirmed at publication time, and assessed with low-to-moderate confidence that the operator was a Chinese-speaking or Sinophone threat actor based on infrastructure history, Chinese-language indicators, and use of FOFA.

Jul 24
Ahnlab Asec

Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN - ASEC

Jul 24
Security Affairs

Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

Jul 24
The Hacker News

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Jul 24
Bleeping Computer

Hermes AI agent used to automate attack on Thai Finance Ministry

Jul 23
Cyberveille

Ministère des Finances thaïlandais ciblé par un agent IA autonome Hermes et l'implant Hades | CyberVeille

Jul 23
Huntio

Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.