logo

Vshell Gains Traction Among Threat Actors as an Alternative to Cobalt Strike

ID: efb5aed6-3871-505a-bec0-0bd75c296315

STIX ID: report--efb5aed6-3871-505a-bec0-0bd75c296315

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-27

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Executive summary:** Vshell is a Go-based C2/RAT that has evolved from a lightweight tool into a multi-protocol, actively used post-compromise framework—supporting TCP, KCP/UDP, WebSocket, DNS/DoH/DoT, and S3/OSS channels—with features to evade detection (nginx impersonation, digest auth). Censys telemetry found exposed panels with hundreds of clients and over 850 listeners; the tool has been observed in multiple campaigns including Operation DRAGONCLONE and activity attributed to UNC5174, making it a notable, broadly deployed threat that defenders should hunt for across web-facing infrastructure and encrypted DNS channels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.