logo

China’s new cyber arsenal revealed.

ID: 9dbd6816-3342-59c8-bbc4-1ea4f755ed52

STIX ID: report--9dbd6816-3342-59c8-bbc4-1ea4f755ed52

Feed Name: The CyberWire

Threat Score
85/100

Date Published: 2025-04-26

Date Updated: 2026-04-23

...
...

Sysdig researchers report that UNC5174, a Chinese state-sponsored threat actor, has re-emerged with a stealthy campaign employing a SNOWLIGHT malware variant and the VShell RAT to target Linux systems via malicious bash scripts, domain squatting, and in-memory/fileless payloads; the activity demonstrates high sophistication and espionage intent against research institutions, critical infrastructure, and NGOs across the West and Asia-Pacific.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.