PULSE NAME
UNC5174's evolution in China's ongoing cyber warfare: From SNOWLIGHT to VShell
WHITE UNC5174 AlienVault 2025-04-16 Modified: 2025-04-16
28
IOCs
MEDIUM VOLUME
Chinese state-sponsored threat actor UNC5174 has launched a new campaign using SNOWLIGHT malware and VShell, a Remote Access Trojan. The campaign targets Linux systems, employing domain squatting for phishing and social engineering. SNOWLIGHT acts as a dropper for VShell, which resides in memory as a fileless payload. The attackers use WebSockets for command and control communication, enhancing stealth. UNC5174's motivations include espionage and access brokering. The campaign has been active since November 2024, demonstrating sophisticated techniques such as memory manipulation and defense evasion. This development highlights the threat actor's expanding arsenal and continued support for Chinese government operations.
Indicators of Compromise (3 / 28 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 193beea281b0d13323dffb32483aa661 2025-04-16
FileHash-MD5 90bb96c7a3fd501d7ac0fce143083b85 2025-04-16
FileHash-MD5 96f307b0ba3bb11715fab5db8d61191f 2025-04-16