Vshell C2 Framework — Chinese-Language Cobalt Strike Alternative in APT Campaigns (UNC5174/SNOWLIGHT, Operation DRAGONCLONE)
Vshell C2 Framework (TL-2026-0141), also tracked as Vshell, is a high-severity malware campaign, first published 2026-02-24. It is attributed to UNC5174 (China) with high confidence, affects Multiple Windows Operating Systems, maps to 30 MITRE ATT&CK techniques (T1005, T1016, T1021.001), and is covered by 9 detection rules and 26 indicators of compromise.
Key facts for TL-2026-0141
- Threat ID
- TL-2026-0141
- Also known as
- Vshell, VShell C2, SNOWLIGHT Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-02-24
- Last reviewed
- 2026-02-24
- Attribution
- UNC5174
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government, telecommunications, research, critical-infrastructure, defense, technology, healthcare
- Target regions
- North America, Europe, Asia-Pacific, United Kingdom, France, China
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in Vshell C2 Framework
Malware and tooling: Vshell
Vshell is a Go-based command-and-control framework marketed as a Cobalt Strike alternative within Chinese-speaking offensive-security ecosystems. Active since 2021 with 5 major versions, Vshell provides full post-compromise host management, network pivoting, and in-memory execution. Censys identified 850+ active listeners and exposed panels with 286+ connected client agents. Confirmed in APT campaigns: UNC5174/SNOWLIGHT (targeting US/UK/Canada government and research), Operation DRAGONCLONE (Chinese telecom targeting), and AhnLab-reported incidents using Discord Bot backdoors.
How Vshell C2 Framework works
Vshell is a mature Go-based command-and-control (C2) platform that has evolved from a simple remote access tool into a full-featured adversary simulation framework used by Chinese-speaking threat actors. Originally released in 2021, Vshell's tagline reads 'CobaltStrike难用?来试试vshell吧' (Is Cobalt Strike difficult to use? Try Vshell instead). The framework follows Cobalt Strike's architecture: centralized teamserver managing implants with an operator web interface.
Vshell has undergone 5 significant development milestones: v1 (2021) — teamserver controlled via AntSword; v2 (2022) — local web interface added; v3 (2022) — rebased on NPS (intranet penetration proxy) with forked frontend; v4 (2023) — licensing system, nginx impersonation for C2 evasion, additional protocols; v4.6 (2024) — end of public releases, suspected private/commercial development.
The framework supports multiple listener types: TCP, KCP/UDP, WebSocket, DNS, DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), and Object Storage System (S3). Default listener port is TCP/8084. Both Windows and Linux clients are supported including x86_64 and ARM variants. The interface is natively Mandarin.
Censys scanning reveals over 850 active Vshell listeners and exposed panels with up to 286 connected client agents that can serve as traffic relays for lateral movement and operational proxying. Newer versions use digest authentication to reduce fingerprinting surface.
Confirmed APT usage includes:
1. UNC5174/SNOWLIGHT Campaign (Sysdig TRT, 2025): Chinese state-sponsored contractor targeting US, Canada, UK government organizations, research institutions, and critical infrastructure. SNOWLIGHT dropper deploys fileless VShell payload via memfd (in-memory execution on Linux). WebSocket-based C2 communication. Domain squatting impersonating Google, Cloudflare, Telegram, and Huione Pay. Also deploys Sliver and Cobalt Strike. Uses crontab and systemd for persistence. C2 domains: gooogleasia[.]com, sex666vr[.]com, c1oudf1are[.]com, telegrams[.]icu, huionepay[.]me.
2. Operation DRAGONCLONE (Seqrite Labs, 2025): Targeting Chinese telecom (China Mobile Tietong subsidiary). DLL sideloading via trojanized Wondershare Repairit installer. VELETRIX loader uses IPFuscation (shellcode encoded as IPv4 addresses), anti-sandbox via Sleep/Beep/NtDelayExecution, VirtualAllocExNuma, and EnumCalendarInfoA callback execution. Decrypts VShell implant (tcp_windows_amd64.dll) in memory. Salt: qwe123qwe. 44 implants identified with same salt. Infrastructure overlaps with Earth Lamia and SAP NetWeaver CVE-2025-31324 exploitation.
3. AhnLab ASEC (Nov 2025): UNC5174 deploying Discord Bot backdoor using discordgo library after initial VShell compromise. Bot uses Discord API as C2 channel (MessageCreate events). Capabilities: command execution (bash -c), file upload/download, system info collection. AES-encrypted bot tokens. VirusTotal detection: 1/64 (AhnLab only).
Vshell's growing adoption signals a shift in Chinese offensive ecosystems away from Cobalt Strike toward purpose-built, lower-detection alternatives. The framework's cross-platform support, multiple protocol options, and in-memory execution make it a significant threat to defenders.
MITRE ATT&CK techniques used in TL-2026-0141
collection
discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery
lateral-movement
T1021.001 Remote Desktop Protocol
defense-evasion
T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1055.012 Process Hollowing; T1070.004 File Deletion; T1497.003 Time Based Checks; T1620 Reflective Code Loading
exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
execution
T1053.003 Cron; T1059.004 Unix Shell; T1204.002 Malicious File; T1569.002 Service Execution
command-and-control
T1071.001 Web Protocols; T1071.004 DNS; T1090.003 Multi-hop Proxy; T1102.002 Bidirectional Communication; T1219 Remote Access Tools; T1572 Protocol Tunneling; T1573.002 Asymmetric Cryptography
initial-access
T1190 Exploit Public-Facing Application; T1566.001 Spearphishing Attachment
persistence
stealth
resource-development
Affected products and versions in Vshell C2 Framework
- Multiple — Windows Operating Systems
Vulnerable versions: All versions (x86_64) - Multiple — Linux Operating Systems
Vulnerable versions: All versions (x86_64, ARM)
Remediation for Vshell C2 Framework
Immediate actions
- Block known Vshell C2 domains at DNS/proxy: gooogleasia.com, sex666vr.com, c1oudf1are.com, telegrams.icu, huionepay.me
- Hunt for TCP/8084 listeners and WebSocket connections to unknown infrastructure
- Scan for NPS-based intranet proxying indicators on endpoints
- Block Discord Bot API traffic from non-approved endpoints
- Hunt for memfd-based fileless execution on Linux systems
Workarounds
- Restrict outbound WebSocket connections to known services
- Monitor for discordgo library usage in unauthorized Go binaries
- Alert on EnumCalendarInfoA callback execution from non-standard processes
Longer-term hardening
- Deploy behavioral detection for DLL sideloading via signed binaries loading unsigned DLLs
- Monitor for IPFuscation patterns (RtlIpv4StringToAddressA API abuse)
- Implement DNS-over-HTTPS/DoT monitoring to detect alternative C2 channels
- Audit crontab and systemd services for unauthorized persistence
- Block traffic to Censys-identified Vshell listener IPs
Weaknesses (CWE) in Vshell C2 Framework
CWE-506, CWE-912
Timeline of Vshell C2 Framework
- Vshell v1 released on GitHub by Chinese developer. Teamserver component controlled via AntSword (蚁剑). No web UI.
- Vshell v2 adds local web interface. v3 rebases on NPS (intranet penetration proxy) with forked frontend, significantly expanding capabilities.
- Vshell v4 introduces licensing system, nginx impersonation for C2 evasion, interface redesign, and additional protocols. Tagline: 'CobaltStrike难用?来试试vshell吧'.
- Vshell v4.6 marks end of public releases. Development goes private, suspected commercial sale to threat actors.
- First samples of SNOWLIGHT dropper deploying fileless VShell payload detected on VirusTotal. UNC5174 campaign targeting government and research institutions via domain squatting (gooogleasia.com).
- Seqrite Labs discovers Operation DRAGONCLONE targeting China Mobile Tietong. VELETRIX loader uses DLL sideloading via Wondershare Repairit, IPFuscation shellcode encoding, and in-memory VShell deployment.
- AhnLab ASEC reports UNC5174 deploying Discord Bot backdoor using discordgo library as fallback C2 channel after initial VShell compromise. 1/64 VT detection rate.
- Censys publishes comprehensive Vshell analysis. 850+ active listeners detected via internet scanning. Exposed panels with 286+ connected agents. Framework now considered mature post-exploitation capability. Source: https://censys.com/blog/vshell/
- As of 2026-05-29, Vshell remains an active, growing threat: Censys (Feb 2026) tracks 850+ live listeners and a panel with 286 agents, and 2026 reporting shows widening adoption. UNC5174/Earth Lamia (China espionage) is still operating with no takedown; no CVE applies (offensive C2 tool, not a vuln) and no successor supersedes it.
Sources cited for Vshell C2 Framework
- Censys: Vshell — A Chinese-Language Alternative to Cobalt Strike
- Sysdig TRT: UNC5174's Evolution — From SNOWLIGHT to VShell
- Seqrite Labs: Operation DRAGONCLONE — Chinese Telecom Veletrix VShell Malware
- NVISO: VShell Analysis Report
- AhnLab ASEC: UNC5174 Group Discord Bot Backdoor Malware
- Trellix: The Silent Fileless Threat of VShell
- ANSSI: French Cyber Threat Overview 2024 — UNC5174 Activity
- Mandiant: Initial Access Brokers Exploit F5 ScreenConnect — UNC5174
Threats related to Vshell C2 Framework
Detection coverage for TL-2026-0141
As of 2026-02-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0141 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.