Skip to content
Malware family LinuxmacOSWindows

VShell

VShell is a publicly available Go-based backdoor and remote access implant used in intrusions across Linux, Windows, and macOS environments.

Profile source: Mallory opens in a new tab

VShell

Family profile

VShell is a publicly available Go-based backdoor and remote access implant used in intrusions across Linux, Windows, and macOS environments. It is commonly described as a fully featured remote administration implant and has been repeatedly observed in operations linked to Chinese-speaking and China-aligned threat actors, although its availability and use in criminal ecosystems mean its presence alone is not sufficient for attribution.

VShell provides post-compromise remote access capabilities including interactive shell access, arbitrary command execution, file operations, port forwarding, screenshot capture, and proxying functionality. Multiple reports describe it as supporting broad remote administration and post-exploitation control on compromised systems, especially internet-facing servers. In several observed Linux deployments, VShell was executed directly in memory and paired with process masquerading to reduce visibility, including renaming itself to resemble a kernel worker thread. It has also been delivered through stagers and custom loaders that decrypt or decode the implant in memory before execution.

Observed delivery chains show VShell used as a follow-on payload after exploitation rather than as a primary initial-access mechanism. It has been deployed after exploitation of public-facing applications including Roundcube, Trimble Cityworks, BeyondTrust Remote Support, and mass exploitation of vulnerable WordPress and other CMS components. In these campaigns, operators used webshells, shell scripts, Rust-based loaders, or ELF droppers such as SNOWLIGHT and TetraLoader to install or inject VShell. Some campaigns used it as a fallback persistence and remote-access option when webshell deployment failed.

Victimology associated with VShell spans universities, government and public-sector networks, financial services, healthcare, legal services, technology organizations, utilities-related environments, and broadly exposed web infrastructure. It has appeared in espionage-oriented campaigns targeting research institutions and public-sector entities as well as financially motivated mass-exploitation and access-brokerage operations. The malware’s cross-platform support, in-memory execution patterns, and compatibility with broader Chinese-speaking offensive tooling ecosystems have made it a recurring implant in both targeted and opportunistic intrusions.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Process Injection
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 14, 2026
Last activity
Jul 19, 2026
Feed role
C2
Host form
42 IP / 0 hostnames

Leading locations

  • HK26
  • CN7
  • US6
  • BR1
  • NL1
  • SG1

Leading providers

  • GNET INC.21
  • Hangzhou Alibaba Advertising Co.,Ltd.4
  • Shenzhen Tencent Computer Systems Company Limited3
  • Kaopu Cloud HK Limited2
  • Cloudie Limited1
  • cognetcloud INC1

Infrastructure traits

  • Hosting 41

Samples

Recent associated samples

Reported operators

Threat actors

13 named in public reporting
UNK_MassTraction

В противном случае малварь загружает шелл-скрипт, который запускает прямо в памяти VShell — написанный на Go бэкдор, поддерживающий открытие интерактивного шелла и проброс портов.

UNC5174

For its own remote access, the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list.

UAT-6382

Talos has so far found two types of payloads deployed by TetraLoader on the infected endpoints: ... VShell stager ... The payload received by the VShell stager is in fact the actual VShell implant. VShell is a GoLang-based implant that talks to its C2 and provides a wide variety of remote access trojan-based functionalities.

UAT-8302

The group deploys NetDraft, a .NET-based backdoor linked to the FinDraft and SquidDoor family, alongside an updated version of the CloudSorcerer backdoor and the VSHELL implant.

UNC6586

SNOWLIGHT, a VShell stager... The attack chains culminate in the deployment of NetDraft, CloudSorcerer (version 3.0), and VShell.

Earth Alux

VELETRIX carries a VShell shellcode which is an Offensive Security Tool, like Meterpreter, Cobalt Strike among others, which means that, when executed, it will communicate with the Command and Control server.

Earth Lamia

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Jackpot Panda

China-nexus groups (i.e., Earth Lamia, Jackpot Panda, UNC5174) deploying Cobalt Strike beacons, Sliver, and Vshell backdoors

Earth Krahang

After gaining access, the operators deployed SnakeC2, NEOBEACON (which abuses OneDrive and the Microsoft Graph API for C2), Cobalt Strike, VShell, and SoftEther VPN.

APT41

After gaining access, the operators deployed SnakeC2, NEOBEACON (which abuses OneDrive and the Microsoft Graph API for C2), Cobalt Strike, VShell, and SoftEther VPN.

Silver Fox

"The malware used in the campaign included ValleyRAT and VShell."

HAFNIUM

"CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments."

TGR-STA-1030

Among the tools put to use by the threat actor are command-and-control (C2) frameworks... VShell

Exploited software

Vulnerabilities linked to VShell

20 CVEs
CVE-2025-49113 Post-Auth RCE in Roundcube Webmail via PHP Object Deserialization CVE-2020-25213 Unauthenticated Arbitrary File Upload and RCE in WordPress WP File Manager CVE-2025-34085 Rejected duplicate of CVE-2020-36847 in WordPress Simple File List CVE-2026-0740 Unauthenticated Arbitrary File Upload in Ninja Forms File Uploads for WordPress CVE-2026-3844 Unauthenticated Arbitrary File Upload in Breeze Cache for WordPress CVE-2026-6433 SQL injection to PHP code execution in Custom CSS JS PHP WordPress plugin CVE-2026-1969 Arbitrary File Upload in ThemeREX Addons for WordPress CVE-2026-48907 Unauthenticated RCE in Joomla JCE Profile Import CVE-2025-12057 Arbitrary File Upload in WavePlayer WordPress Plugin CVE-2025-7852 Arbitrary File Upload in WPBookit WordPress Plugin CVE-2025-7443 Arbitrary File Upload in BerqWP WordPress Plugin CVE-2024-42009 Stored XSS in Roundcube message_body() CVE-2023-2868 Remote Command Injection in Barracuda Email Security Gateway CVE-2025-0994 Remote Code Execution in Trimble Cityworks Deserialization CVE-2025-0944 SQL Injection in itsourcecode Tailoring Management System 1.0 customerview.php CVE-2026-1731 Pre-auth OS Command Injection RCE in BeyondTrust Remote Support and Privileged Remote Access CVE-2025-55182 React2Shell CVE-2025-42999 Insecure Deserialization in SAP NetWeaver Visual Composer Metadata Uploader CVE-2024-23897 Jenkins CLI arbitrary file read CVE-2025-31324 Unauthenticated Arbitrary File Upload in SAP NetWeaver Visual Composer Metadata Uploader

MITRE ATT&CK

VShell in ATT&CK

37 distinct techniques

Reporting

Research mentioning VShell

Jul 15
Cyberaccord

Chinese Hackers Embed Claude Code and DeepSeek in AI-Powered Government Cyberattacks - Cyber Accord

The primary collection node 112.213.124[.]132 hosted a multi-tiered offensive toolkit featuring the ARL (Attack Reconnaissance Lighthouse) framework for network mapping, DeepAudit for vulnerability identification, and Vshell for remote system administration.

Jul 15
Xakep

Уязвимости в Roundcube используются для слежки за учеными - Хакер

В противном случае малварь загружает шелл-скрипт, который запускает прямо в памяти VShell — написанный на Go бэкдор, поддерживающий открытие интерактивного шелла и проброс портов.

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

VSHell6

Jul 10
Trojan Killer News

WP-SHELLSTORM Webshells Hit WordPress Sites

Observed duration 22 days for the exposed campaign window Notable follow-on tooling SNOWLIGHT stager and VShell implant with process masquerading

Jul 10
The Hacker News

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

For its own remote access, the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list.

Jul 9
Scworld

Suspected Chinese spies target universities with Roundcube exploit | brief | SC Media

The attackers then use a deserialization exploit, CVE-2025-49113, to install a webshell called SquareShell and a VShell implant, enabling remote code execution.

Jul 9
Socradar

How WP-SHELLSTORM Exposed 1.4M WordPress Sites

The implant itself, identified as VShell, takes deliberate steps to avoid detection: once running, it renames its own process to “[kworker/0:2]”...

Jul 8
Gurucul Threat Research

One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation | Community Portal | Gurucul

Successful attacks steal credentials, install webshells, or deploy memory-resident VShell backdoors.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.