Vshell C2 Framework — Chinese-Language Cobalt Strike Alternative in APT Campaigns (UNC5174/SNOWLIGHT, Operation DRAGONCLONE)

Vshell C2 Framework (TL-2026-0141), also tracked as Vshell, is a high-severity malware campaign, first published 2026-02-24. It is attributed to UNC5174 (China) with high confidence, affects Multiple Windows Operating Systems, maps to 30 MITRE ATT&CK techniques (T1005, T1016, T1021.001), and is covered by 9 detection rules and 26 indicators of compromise.

Key facts for TL-2026-0141

Threat ID
TL-2026-0141
Also known as
Vshell, VShell C2, SNOWLIGHT Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-02-24
Last reviewed
2026-02-24
Attribution
UNC5174
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government, telecommunications, research, critical-infrastructure, defense, technology, healthcare
Target regions
North America, Europe, Asia-Pacific, United Kingdom, France, China
Detection rules
9
Indicators of compromise
26

Malware and tooling in Vshell C2 Framework

Malware and tooling: Vshell

Vshell is a Go-based command-and-control framework marketed as a Cobalt Strike alternative within Chinese-speaking offensive-security ecosystems. Active since 2021 with 5 major versions, Vshell provides full post-compromise host management, network pivoting, and in-memory execution. Censys identified 850+ active listeners and exposed panels with 286+ connected client agents. Confirmed in APT campaigns: UNC5174/SNOWLIGHT (targeting US/UK/Canada government and research), Operation DRAGONCLONE (Chinese telecom targeting), and AhnLab-reported incidents using Discord Bot backdoors.

How Vshell C2 Framework works

Vshell is a mature Go-based command-and-control (C2) platform that has evolved from a simple remote access tool into a full-featured adversary simulation framework used by Chinese-speaking threat actors. Originally released in 2021, Vshell's tagline reads 'CobaltStrike难用?来试试vshell吧' (Is Cobalt Strike difficult to use? Try Vshell instead). The framework follows Cobalt Strike's architecture: centralized teamserver managing implants with an operator web interface.

Vshell has undergone 5 significant development milestones: v1 (2021) — teamserver controlled via AntSword; v2 (2022) — local web interface added; v3 (2022) — rebased on NPS (intranet penetration proxy) with forked frontend; v4 (2023) — licensing system, nginx impersonation for C2 evasion, additional protocols; v4.6 (2024) — end of public releases, suspected private/commercial development.

The framework supports multiple listener types: TCP, KCP/UDP, WebSocket, DNS, DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), and Object Storage System (S3). Default listener port is TCP/8084. Both Windows and Linux clients are supported including x86_64 and ARM variants. The interface is natively Mandarin.

Censys scanning reveals over 850 active Vshell listeners and exposed panels with up to 286 connected client agents that can serve as traffic relays for lateral movement and operational proxying. Newer versions use digest authentication to reduce fingerprinting surface.

Confirmed APT usage includes:

1. UNC5174/SNOWLIGHT Campaign (Sysdig TRT, 2025): Chinese state-sponsored contractor targeting US, Canada, UK government organizations, research institutions, and critical infrastructure. SNOWLIGHT dropper deploys fileless VShell payload via memfd (in-memory execution on Linux). WebSocket-based C2 communication. Domain squatting impersonating Google, Cloudflare, Telegram, and Huione Pay. Also deploys Sliver and Cobalt Strike. Uses crontab and systemd for persistence. C2 domains: gooogleasia[.]com, sex666vr[.]com, c1oudf1are[.]com, telegrams[.]icu, huionepay[.]me.

2. Operation DRAGONCLONE (Seqrite Labs, 2025): Targeting Chinese telecom (China Mobile Tietong subsidiary). DLL sideloading via trojanized Wondershare Repairit installer. VELETRIX loader uses IPFuscation (shellcode encoded as IPv4 addresses), anti-sandbox via Sleep/Beep/NtDelayExecution, VirtualAllocExNuma, and EnumCalendarInfoA callback execution. Decrypts VShell implant (tcp_windows_amd64.dll) in memory. Salt: qwe123qwe. 44 implants identified with same salt. Infrastructure overlaps with Earth Lamia and SAP NetWeaver CVE-2025-31324 exploitation.

3. AhnLab ASEC (Nov 2025): UNC5174 deploying Discord Bot backdoor using discordgo library after initial VShell compromise. Bot uses Discord API as C2 channel (MessageCreate events). Capabilities: command execution (bash -c), file upload/download, system info collection. AES-encrypted bot tokens. VirusTotal detection: 1/64 (AhnLab only).

Vshell's growing adoption signals a shift in Chinese offensive ecosystems away from Cobalt Strike toward purpose-built, lower-detection alternatives. The framework's cross-platform support, multiple protocol options, and in-memory execution make it a significant threat to defenders.

MITRE ATT&CK techniques used in TL-2026-0141

collection

T1005 Data from Local System

discovery

T1016 System Network Configuration Discovery; T1082 System Information Discovery

lateral-movement

T1021.001 Remote Desktop Protocol

defense-evasion

T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1055.012 Process Hollowing; T1070.004 File Deletion; T1497.003 Time Based Checks; T1620 Reflective Code Loading

exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

execution

T1053.003 Cron; T1059.004 Unix Shell; T1204.002 Malicious File; T1569.002 Service Execution

command-and-control

T1071.001 Web Protocols; T1071.004 DNS; T1090.003 Multi-hop Proxy; T1102.002 Bidirectional Communication; T1219 Remote Access Tools; T1572 Protocol Tunneling; T1573.002 Asymmetric Cryptography

initial-access

T1190 Exploit Public-Facing Application; T1566.001 Spearphishing Attachment

persistence

T1543.002 Systemd Service

stealth

T1574.001 DLL

resource-development

T1583.001 Domains; T1587.001 Malware; T1588.002 Tool

Affected products and versions in Vshell C2 Framework

  • Multiple — Windows Operating Systems
    Vulnerable versions: All versions (x86_64)
  • Multiple — Linux Operating Systems
    Vulnerable versions: All versions (x86_64, ARM)

Remediation for Vshell C2 Framework

Immediate actions

  • Block known Vshell C2 domains at DNS/proxy: gooogleasia.com, sex666vr.com, c1oudf1are.com, telegrams.icu, huionepay.me
  • Hunt for TCP/8084 listeners and WebSocket connections to unknown infrastructure
  • Scan for NPS-based intranet proxying indicators on endpoints
  • Block Discord Bot API traffic from non-approved endpoints
  • Hunt for memfd-based fileless execution on Linux systems

Workarounds

  • Restrict outbound WebSocket connections to known services
  • Monitor for discordgo library usage in unauthorized Go binaries
  • Alert on EnumCalendarInfoA callback execution from non-standard processes

Longer-term hardening

  • Deploy behavioral detection for DLL sideloading via signed binaries loading unsigned DLLs
  • Monitor for IPFuscation patterns (RtlIpv4StringToAddressA API abuse)
  • Implement DNS-over-HTTPS/DoT monitoring to detect alternative C2 channels
  • Audit crontab and systemd services for unauthorized persistence
  • Block traffic to Censys-identified Vshell listener IPs

Weaknesses (CWE) in Vshell C2 Framework

CWE-506, CWE-912

Timeline of Vshell C2 Framework

  • Vshell v1 released on GitHub by Chinese developer. Teamserver component controlled via AntSword (蚁剑). No web UI.
  • Vshell v2 adds local web interface. v3 rebases on NPS (intranet penetration proxy) with forked frontend, significantly expanding capabilities.
  • Vshell v4 introduces licensing system, nginx impersonation for C2 evasion, interface redesign, and additional protocols. Tagline: 'CobaltStrike难用?来试试vshell吧'.
  • Vshell v4.6 marks end of public releases. Development goes private, suspected commercial sale to threat actors.
  • First samples of SNOWLIGHT dropper deploying fileless VShell payload detected on VirusTotal. UNC5174 campaign targeting government and research institutions via domain squatting (gooogleasia.com).
  • Seqrite Labs discovers Operation DRAGONCLONE targeting China Mobile Tietong. VELETRIX loader uses DLL sideloading via Wondershare Repairit, IPFuscation shellcode encoding, and in-memory VShell deployment.
  • AhnLab ASEC reports UNC5174 deploying Discord Bot backdoor using discordgo library as fallback C2 channel after initial VShell compromise. 1/64 VT detection rate.
  • Censys publishes comprehensive Vshell analysis. 850+ active listeners detected via internet scanning. Exposed panels with 286+ connected agents. Framework now considered mature post-exploitation capability. Source: https://censys.com/blog/vshell/
  • As of 2026-05-29, Vshell remains an active, growing threat: Censys (Feb 2026) tracks 850+ live listeners and a panel with 286 agents, and 2026 reporting shows widening adoption. UNC5174/Earth Lamia (China espionage) is still operating with no takedown; no CVE applies (offensive C2 tool, not a vuln) and no successor supersedes it.

Sources cited for Vshell C2 Framework

Threats related to Vshell C2 Framework

Detection coverage for TL-2026-0141

As of 2026-02-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0141 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats