logo

UNC5174’s evolution in China’s ongoing cyber warfare: From SNOWLIGHT to VShell

ID: 02f40bed-a353-507b-9ea9-438f182208f0

STIX ID: report--02f40bed-a353-507b-9ea9-438f182208f0

Feed Name: Sysdig Blog

Threat Score
90/100

Date Published: 2025-04-15

Date Updated: 2026-05-01

...
...

Sysdig’s report details an active UNC5174 (Chinese state-affiliated) campaign that uses the SNOWLIGHT dropper to deliver a fileless VShell RAT (executed via memfd/fexecve) and Sliver implants to Linux hosts, leveraging WebSocket-based C2 on impersonated domains (e.g., gooogleasia.com, sex666vr.com). The analysis includes decompiled code, behavioral artifacts, IOCs (domains, IPs, SHA256s), and detection guidance (Falco rules and a YARA rule) to identify the fileless payload, memory allocation patterns, and network indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.