UNC5174’s evolution in China’s ongoing cyber warfare: From SNOWLIGHT to VShell
ID: 02f40bed-a353-507b-9ea9-438f182208f0
STIX ID: report--02f40bed-a353-507b-9ea9-438f182208f0
Feed Name: Sysdig Blog
Sysdig’s report details an active UNC5174 (Chinese state-affiliated) campaign that uses the SNOWLIGHT dropper to deliver a fileless VShell RAT (executed via memfd/fexecve) and Sliver implants to Linux hosts, leveraging WebSocket-based C2 on impersonated domains (e.g., gooogleasia.com, sex666vr.com). The analysis includes decompiled code, behavioral artifacts, IOCs (domains, IPs, SHA256s), and detection guidance (Falco rules and a YARA rule) to identify the fileless payload, memory allocation patterns, and network indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
