Skip to content

VShell

VShell is a Go-based, cross-platform remote-access trojan and backdoor supporting Windows, Linux, and macOS/Darwin systems.

Profile source: Mallory opens in a new tab

VShell

Family profile

VShell is a Go-based, cross-platform remote-access trojan and backdoor supporting Windows, Linux, and macOS/Darwin systems. It provides interactive command execution, file browsing and transfer, screenshot capture, network discovery, and proxy/tunneling functions, including SOCKS5, HTTP, and TCP/UDP proxying for pivoting and data movement. It supports multiple command-and-control transports, including TCP, UDP, WebSockets, DNS, DNS-over-HTTPS, DNS-over-TLS, and object-storage services, and uses encrypted communications.

VShell is commonly deployed after compromise of public-facing systems, including edge appliances and webmail infrastructure, and has also been delivered through spearphishing lures as a later-stage payload. It supports shellcode, stager, and full-beacon payload formats, in-memory execution, plugins, and persistence features. Versions have incorporated anti-sandbox functionality, encrypted traffic, reduced command logging, and eBPF-related support. VShell has been used in long-running espionage, pre-positioning, and access-brokering activity, as well as financially motivated intrusions. It has been associated with UNC5174, Houken, UNK_MassTraction, and other clusters, but its use alone is not sufficient to attribute an intrusion to any one actor. Victims have included government, healthcare, military, research, academic, telecommunications, finance, transport, and technology organizations worldwide.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 6, 2026
Last activity
Sep 12, 2026
Feed role
C2 / Distribution
Host form
65 IP / 3 hostnames

Leading locations

  • CN32
  • US12
  • HK11
  • SG7
  • JP2
  • KR2
  • AT1
  • TW1

Leading providers

  • Shenzhen Tencent Computer Systems Company Limited16
  • Hangzhou Alibaba Advertising Co.,Ltd.8
  • Tencent Building, Kejizhongyi Avenue5
  • Alibaba (US) Technology Co., Ltd.3
  • Turing Group Limited3
  • China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch2

Infrastructure traits

  • Hosting 61
  • Anycast 2

Samples

Recent associated samples

Reported operators

Threat actors

15 named in public reporting
UNK_MassTraction

UNK_MassTraction repeatedly exploited Roundcube vulnerabilities to infiltrate university networks and used IceCube, SquareShell, and VShell.

UNC5174

Houken operators used open-source tools previously detailed as part of UNC5174 intrusion set such as: GOREVERSE, VShell, fscan or ffuff.

Earth Lumina

VShell is a full-fledged remote access trojan (RAT), programmed in Go... It has offensive capabilities such as capturing screenshots of victim computers, allows for browsing as well as uploading and downloading files, and the ability to remotely execute commands as a backdoor.

Larva-26009

the attacker installed VShell and GotoHTTP to gain control over the infected system

UAT-6382

Talos has so far found two types of payloads deployed by TetraLoader on the infected endpoints: ... VShell stager ... The payload received by the VShell stager is in fact the actual VShell implant. VShell is a GoLang-based implant that talks to its C2 and provides a wide variety of remote access trojan-based functionalities.

UAT-8302

The group deploys NetDraft, a .NET-based backdoor linked to the FinDraft and SquidDoor family, alongside an updated version of the CloudSorcerer backdoor and the VSHELL implant.

UNC6586

SNOWLIGHT, a VShell stager... The attack chains culminate in the deployment of NetDraft, CloudSorcerer (version 3.0), and VShell.

Jewelbug

VELETRIX carries a VShell shellcode which is an Offensive Security Tool, like Meterpreter, Cobalt Strike among others, which means that, when executed, it will communicate with the Command and Control server.

Earth Lamia

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Jackpot Panda

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Earth Krahang

After gaining access, the operators deployed SnakeC2, NEOBEACON (which abuses OneDrive and the Microsoft Graph API for C2), Cobalt Strike, VShell, and SoftEther VPN.

Earth Lusca

After gaining access, the operators deployed SnakeC2, NEOBEACON (which abuses OneDrive and the Microsoft Graph API for C2), Cobalt Strike, VShell, and SoftEther VPN.

Silver Fox

"The malware used in the campaign included ValleyRAT and VShell."

HAFNIUM

"CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments."

TGR-STA-1030

Among the tools put to use by the threat actor are command-and-control (C2) frameworks... VShell

Exploited software

Vulnerabilities linked to VShell

22 CVEs
CVE-2025-31324 Unauthenticated Arbitrary File Upload RCE in SAP NetWeaver Visual Composer Metadata Uploader CVE-2024-23897 Jenkins CLI Arbitrary File Read CVE-2025-41244 Local Privilege Escalation in VMware Aria Operations and VMware Tools Service Discovery CVE-2024-36401 GeoServer GeoTools XPath Evaluation Remote Code Execution CVE-2025-49113 Authenticated RCE in Roundcube Webmail upload.php via PHP Object Deserialization CVE-2020-25213 Unauthenticated Arbitrary File Upload RCE in WordPress File Manager CVE-2025-34085 Rejected duplicate of CVE-2020-36847 in WordPress Simple File List CVE-2026-0740 Unauthenticated Arbitrary File Upload in Ninja Forms - File Uploads for WordPress CVE-2026-3844 Unauthenticated Arbitrary File Upload in Breeze Cache for WordPress CVE-2026-6433 Unauthenticated SQL Injection to PHP Code Execution in Custom CSS JS & PHP WordPress Plugin CVE-2026-1969 Arbitrary File Upload in ThemeREX Addons for WordPress CVE-2026-48907 Unauthenticated RCE in Joomla JCE profiles import CVE-2025-12057 Arbitrary File Upload and RCE in WavePlayer WordPress Plugin CVE-2025-7852 Arbitrary File Upload in WPBookit WordPress Plugin CVE-2025-7443 Arbitrary File Upload in BerqWP WordPress Plugin CVE-2024-42009 Roundcube Webmail XSS in message_body() CVE-2023-2868 Barracuda Email Security Gateway .tar Command Injection CVE-2025-0994 Remote Code Execution in Trimble Cityworks Deserialization CVE-2025-0944 SQL Injection in itsourcecode Tailoring Management System 1.0 customerview.php CVE-2026-1731 Pre-authentication OS Command Injection in BeyondTrust Remote Support and Privileged Remote Access CVE-2025-55182 React2Shell CVE-2025-42999 Insecure Deserialization in SAP NetWeaver Visual Composer Metadata Uploader

MITRE ATT&CK

VShell in ATT&CK

46 distinct techniques

Reporting

Research mentioning VShell

Jul 29
Malware News

Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN - Malware Analysis - Malware Analysis, News and Indicators

A targeted attack on an MS-SQL server led to the deployment of XMRig CoinMiner along with multiple remote-access tools, according to AhnLab ASEC. The intrusion was attributed to the Larva-26009 threat actor, which went beyond the common pattern of opportunistic cryptomining on exposed SQL servers by also installing VShell, GotoHTTP, and SoftEther VPN to maintain control over the compromised system. The toolset indicates the attackers sought both monetization and persistent remote administration after the initial compromise. While coin miners are frequently observed in attacks against internet-exposed Microsoft SQL Server instances, the addition of tunneling and remote-management software suggests a more deliberate post-compromise operation designed to preserve access and expand attacker control over the victim environment.

Jul 24
Scworld

AI assistant used in cyberattack on Thailand's Ministry of Finance | brief | SC Media

Researchers reported an active espionage intrusion targeting Thailand’s Ministry of Finance, tied to exposed attacker infrastructure at 43.246.208[.]207 and additional linked hosts in Hong Kong and Malaysia. The operation used the open-source Hermes autonomous AI agent in unattended "YOLO" mode to enumerate ministry systems, map internal services, and assess privilege-escalation paths, while a previously undocumented cross-platform Go implant dubbed Hades was staged to maintain persistence on both Windows and Linux systems. Investigators also linked a VShell C2 server and the domain redhatupdating432.dnsrd.com to the activity. Recovered artifacts showed targeting of ministry administrative panels, mail infrastructure, Apache Hadoop and HiveServer2 environments, Apache Ambari, GlassFish, Alfresco, and internal document systems. The exposed directories contained exploit code, web shells, stolen credentials, credential-testing scripts, and Linux and IIS exploitation or privilege-escalation modules, while Hades reportedly supported command and control, file transfer, proxying, and screen capture. Investigators said the evidence indicates compromised internal access, though no data exfiltration had been confirmed at publication time, and assessed with low-to-moderate confidence that the operator was a Chinese-speaking or Sinophone threat actor based on infrastructure history, Chinese-language indicators, and use of FOFA.

Jul 24
Ahnlab Asec

Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN - ASEC

Jul 24
Security Affairs

Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

Jul 24
The Hacker News

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Jul 24
Bleeping Computer

Hermes AI agent used to automate attack on Thai Finance Ministry

Jul 23
Cyberveille

Ministère des Finances thaïlandais ciblé par un agent IA autonome Hermes et l'implant Hades | CyberVeille

Jul 23
Huntio

Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.