PULSE NAME
UNC5174's evolution in China's ongoing cyber warfare: From SNOWLIGHT to VShell
WHITE UNC5174 AlienVault 2025-04-16 Modified: 2025-04-16
28
IOCs
MEDIUM VOLUME
Chinese state-sponsored threat actor UNC5174 has launched a new campaign using SNOWLIGHT malware and VShell, a Remote Access Trojan. The campaign targets Linux systems, employing domain squatting for phishing and social engineering. SNOWLIGHT acts as a dropper for VShell, which resides in memory as a fileless payload. The attackers use WebSockets for command and control communication, enhancing stealth. UNC5174's motivations include espionage and access brokering. The campaign has been active since November 2024, demonstrating sophisticated techniques such as memory manipulation and defense evasion. This development highlights the threat actor's expanding arsenal and continued support for Chinese government operations.
Indicators of Compromise (28)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 193beea281b0d13323dffb32483aa661 2025-04-16
FileHash-MD5 90bb96c7a3fd501d7ac0fce143083b85 2025-04-16
FileHash-MD5 96f307b0ba3bb11715fab5db8d61191f 2025-04-16
FileHash-SHA1 0fbac5c94f32b0e011baf39df82a65d293b14e7d 2025-04-16
FileHash-SHA1 6125e88f6c8cbe8c19236fdba7f3d69d104bbbb6 2025-04-16
FileHash-SHA1 a031bd01a0de10b2a5e83f82ca84881835fa9d80 2025-04-16
FileHash-SHA256 21ccb25887eae8b17349cefc04394dc3ad75c289768d7ba61f51d228b4c964db 2025-04-16
FileHash-SHA256 8d88944149ea1477bd7ba0a07be3a4371ba958d4a47b783f7c10cbe08c5e7d38 2025-04-16
FileHash-SHA256 c0838b1211d482d21ccb2c9cc9fb224d1f826474d496a76d21ca18fa2ef92bc1 2025-04-16
FileHash-SHA256 e6db3de3a21debce119b16697ea2de5376f685567b284ef2dee32feb8d2d44f8 2025-04-16
FileHash-SHA1 a97af19c81959c9e3ab62f8b492850dad5db9844 2025-04-16
domain c1oudf1are.com 2025-04-16
domain ciscocdn.com 2025-04-16
domain googlespays.com 2025-04-16
domain huionepay.me 2025-04-16
domain sex666vr.com 2025-04-16
hostname account.gooogleasia.com 2025-04-16
hostname apib.googlespays.com 2025-04-16
hostname btt.evil.gooogleasia.com 2025-04-16
hostname evil.gooogleasia.com 2025-04-16
hostname ks.evil.gooogleasia.com 2025-04-16
hostname lin.c1oudf1are.com 2025-04-16
hostname lin.huionepay.me 2025-04-16
hostname lin.telegrams.icu 2025-04-16
hostname mtls.sex666vr.com 2025-04-16
hostname vs.gooogleasia.com 2025-04-16
hostname wg.gooogleasia.com 2025-04-16
hostname www.bing-server.com 2025-04-16