# SNOWLIGHT

> As of 2026-07-10, SNOWLIGHT is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning vulnerability, malware. ATT&CK coverage spans 49 techniques across 14 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1036.005 (Match Legitimate Resource Name or Location), T1041 (Exfiltration Over C2 Channel).

- **Tracked threats:** 2
- **Categories:** VULNERABILITY, MALWARE
- **As of:** 2026-07-10

## ATT&CK techniques observed

49 techniques observed across 2 of 2 tracked threats. Tactics: Command and Control (10), Stealth (formerly Defense Evasion) (9), Discovery (5), Execution (4), Persistence (4), Resource Development (4).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 2 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 2 tracked threats
- [T1059.004](https://intel.threadlinqs.com/technique/T1059.004) Unix Shell — Execution — observed in 2 of 2 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 2 of 2 tracked threats
- [T1090.003](https://intel.threadlinqs.com/technique/T1090.003) Multi-hop Proxy — Command and Control — observed in 2 of 2 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 2 of 2 tracked threats
- [T1587.001](https://intel.threadlinqs.com/technique/T1587.001) Malware — Resource Development — observed in 2 of 2 tracked threats
- [T1620](https://intel.threadlinqs.com/technique/T1620) Reflective Code Loading — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1021.001](https://intel.threadlinqs.com/technique/T1021.001) Remote Desktop Protocol — Lateral Movement — observed in 1 of 2 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1027.013](https://intel.threadlinqs.com/technique/T1027.013) Encrypted/Encoded File — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1053.003](https://intel.threadlinqs.com/technique/T1053.003) Cron — Persistence — observed in 1 of 2 tracked threats

## Tracked threats

- [WP-SHELLSTORM: Exposed Chinese-Speaking Threat Actor Server Reveals Mass WordPress/Joomla Webshell Brokerage Targeting 1.4M Domains via CVE-2026-48907 (Joomla JCE) and CVE-2021-29441 (Nacos)](https://intel.threadlinqs.com/threat/TL-2026-1180) — HIGH
- [Vshell C2 Framework — Chinese-Language Cobalt Strike Alternative in APT Campaigns (UNC5174/SNOWLIGHT, Operation DRAGONCLONE)](https://intel.threadlinqs.com/threat/TL-2026-0141) — HIGH

## Related CVEs

12 CVEs referenced by tracked SNOWLIGHT activity.

- [CVE-2026-6433](https://intel.threadlinqs.com/cve/CVE-2026-6433)
- [CVE-2026-48907](https://intel.threadlinqs.com/cve/CVE-2026-48907)
- [CVE-2026-3844](https://intel.threadlinqs.com/cve/CVE-2026-3844)
- [CVE-2026-3300](https://intel.threadlinqs.com/cve/CVE-2026-3300)
- [CVE-2026-1969](https://intel.threadlinqs.com/cve/CVE-2026-1969)
- [CVE-2026-0740](https://intel.threadlinqs.com/cve/CVE-2026-0740)
- [CVE-2025-7852](https://intel.threadlinqs.com/cve/CVE-2025-7852)
- [CVE-2025-7443](https://intel.threadlinqs.com/cve/CVE-2025-7443)
- [CVE-2025-12057](https://intel.threadlinqs.com/cve/CVE-2025-12057)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2020-36847](https://intel.threadlinqs.com/cve/CVE-2020-36847)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/SNOWLIGHT
