logo

Vshell: A Chinese-Language Alternative to Cobalt Strike

ID: a2d4d308-cd73-5dd8-8a0e-6f83599d3752

STIX ID: report--a2d4d308-cd73-5dd8-8a0e-6f83599d3752

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2026-02-24

Date Updated: 2026-04-27

Author: Kate Lake; Silas Cutler; Principal Security Researcher

...
...

Vshell is a mature, Go-based command-and-control and post-exploitation platform widely used in Mandarin-speaking offensive ecosystems and observed in real-world incidents in 2025; the report details its architecture, listener types (including TCP/8084, WebSocket, DNS/DoH/DOT, OSS), Censys-derived Internet exposure (hundreds of listeners and panels), and documented usage in campaigns such as DRAGONCLONE and SNOWLIGHT, recommending defenders monitor and hunt for Vshell-related infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.