Vshell: A Chinese-Language Alternative to Cobalt Strike
ID: a2d4d308-cd73-5dd8-8a0e-6f83599d3752
STIX ID: report--a2d4d308-cd73-5dd8-8a0e-6f83599d3752
Feed Name: Censys Blog
Date Published: 2026-02-24
Date Updated: 2026-04-27
Author: Kate Lake; Silas Cutler; Principal Security Researcher
Vshell is a mature, Go-based command-and-control and post-exploitation platform widely used in Mandarin-speaking offensive ecosystems and observed in real-world incidents in 2025; the report details its architecture, listener types (including TCP/8084, WebSocket, DNS/DoH/DOT, OSS), Censys-derived Internet exposure (hundreds of listeners and panels), and documented usage in campaigns such as DRAGONCLONE and SNOWLIGHT, recommending defenders monitor and hunt for Vshell-related infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
