PULSE NAME
UNC5174's evolution in China's ongoing cyber warfare: From SNOWLIGHT to VShell
WHITE UNC5174 AlienVault 2025-04-16 Modified: 2025-04-16
28
IOCs
MEDIUM VOLUME
Chinese state-sponsored threat actor UNC5174 has launched a new campaign using SNOWLIGHT malware and VShell, a Remote Access Trojan. The campaign targets Linux systems, employing domain squatting for phishing and social engineering. SNOWLIGHT acts as a dropper for VShell, which resides in memory as a fileless payload. The attackers use WebSockets for command and control communication, enhancing stealth. UNC5174's motivations include espionage and access brokering. The campaign has been active since November 2024, demonstrating sophisticated techniques such as memory manipulation and defense evasion. This development highlights the threat actor's expanding arsenal and continued support for Chinese government operations.
Indicators of Compromise (4 / 28 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 0fbac5c94f32b0e011baf39df82a65d293b14e7d 2025-04-16
FileHash-SHA1 6125e88f6c8cbe8c19236fdba7f3d69d104bbbb6 2025-04-16
FileHash-SHA1 a031bd01a0de10b2a5e83f82ca84881835fa9d80 2025-04-16
FileHash-SHA1 a97af19c81959c9e3ab62f8b492850dad5db9844 2025-04-16