Vshell C2 Framework — Chinese-Language Cobalt Strike Alternative in APT Campaigns (UNC5174/SNOWLIGHT, Operation DRAGONCLONE) — Threadlinqs Intelligence
As of 2026-05-30, Vshell C2 Framework — Chinese-Language Cobalt Strike Alternative in APT Campaigns (UNC5174/SNOWLIGHT, Operation DRAGONCLONE) is a high-severity malware threat attributed to UNC5174 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-0141 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: UNC5174 · China · ESPIONAGE
Vshell is a Go-based command-and-control framework marketed as a Cobalt Strike alternative within Chinese-speaking offensive-security ecosystems. Active since 2021 with 5 major versions, Vshell
Vshell is a mature Go-based command-and-control (C2) platform that has evolved from a simple remote access tool into a full-featured adversary simulation framework used by Chinese-speaking threat actors. Originally released in 2021, Vshell's tagline reads 'CobaltStrike难用?来试试vshell吧' (Is Cobalt Strike difficult to use? Try Vshell instead). The framework follows Cobalt Strike's architecture: centralized teamserver managing implants with an operator web interface.
Vshell has undergone 5 significant development milestones: v1 (2021) — teamserver controlled via AntSword; v2 (2022) — local web interface added; v3 (2022) — rebased on NPS (intranet penetration proxy) with forked frontend; v4 (2023) — licensing system, nginx impersonation for C2 evasion, additional protocols; v4.6 (2024) — end of public releases, suspected private/commercial development.
The framework supports multiple listener types: TCP, KCP/UDP, WebSocket, DNS, DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), and Object Storage System (S3). Default listener port is TCP/8084. Both Windows and Linux clients are supported including x86_64 and ARM variants. The interface is natively Mandarin.
Censys scanning reveals over 850 active Vshell listeners and exposed panels with up to 286 connected client agents that can serve as traffic relays for lateral movement and operational proxying. Newer versions use digest authentication to reduce fingerprinting surface.
Confirmed APT usage includes:
1. UNC5174/SNOWLIGHT Campaign (Sysdig TRT, 2025): Chinese state-sponsored contractor targeting US, Canada, UK government organizations, research institutions, and critical infrastructure. SNOWLIGHT dropper deploys fileless VShell payload via memfd (in-memory execution on Linux). WebSocket-based C2 communication. Domain squatting impersonating Google, Cloudflare, Telegram, and Huione Pay. Also deploys Sliver and Cobalt Strike. Uses crontab and systemd for persistence. C2 domains: gooogleasia[.]com, sex666vr[.]com, c1oudf1are[.]com, telegrams[.]icu, huionepay[.]me.
2. Operation DRAGONCLONE (Seqrite Labs, 2025): Targeting Chinese telecom (China Mobile Tietong subsidiary). DLL sideloading via trojanized Wondershare Repairit installer. VELETRIX loader uses IPFuscation (shellcode encoded as IPv4 addresses), anti-sandbox via Sleep/Beep/NtDelayExecution, VirtualAllocExNuma, and EnumCalendarInfoA callback execution. Decrypts VShell implant (tcp_windows_amd64.dll) in memory. Salt: qwe123qwe. 44 implants identified with same salt. Infrastructure overlaps with Earth Lamia and SAP NetWeaver CVE-2025-31324 exploitation.
3. AhnLab ASEC (Nov 2025): UNC5174 deploying Discord Bot backdoor using discordgo library after initial VShell compromise. Bot uses Discord API as C2 channel (MessageCreate events). Capabilities: command execution (bash -c), file upload/download, system info collection. AES-encrypted bot tokens. VirusTotal detection: 1/64 (AhnLab only).
Vshell's growing adoption signals a shift in Chinese offensive ecosystems away from Cobalt Strike toward purpose-built, lower-detection alternatives. The framework's cross-platform support, multiple protocol options, and in-memory execution make it a significant threat to defenders.
Weaknesses (CWE)
CWE-506, CWE-912
Target sectors: government, telecommunications, research, critical-infrastructure, defense, technology, healthcare
Target regions: North America, Europe, Asia-Pacific, United Kingdom, France, China
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583.001, T1587.001, T1588.002, T1566.001, T1190, T1059.004, T1204.002, T1569.002, T1053.003, T1543.002