SYMBOLCOMMON_NAMEaka. SYNONYMS
elf.snowlight (Back to overview)

SNOWLIGHT

Actor(s): UNC5174


According to sysdig, SNOWLIGHT is used as a dropper for its fileless payload (vshell).

References
2026-05-05 ⋅ Cisco Talos ⋅ Asheer Malhotra, Brandon White, Jungsoo An
UAT-8302 and its box full of malware
SNOWLIGHT DracuLoader FINALDRAFT SNAPPYBEE STOWAWAY VShell UAT-8302
2025-12-19 ⋅ PolySwarm Tech Team ⋅ PolySwarm
Multiple Threat Actors Leveraging CVE-2025-55182 (React2Shell)
ANGRYREBEL COMPOOD MINOCAT Mirai SNOWLIGHT XMRIG EtherRAT Cobalt Strike Mirai VShell xmrig JACKPOT PANDA
2025-12-12 ⋅ Google ⋅ Aragorn Tseng, Austin Larsen, CASEY CHARRIER, Genevieve Stark, Robert Weiner, Zander Work
Multiple Threat Actors Exploit React2Shell (CVE-2025-55182)
ANGRYREBEL COMPOOD MINOCAT SNOWLIGHT Earth Lamia JACKPOT PANDA
2025-05-13 ⋅ EclecticIQ ⋅ Arda Büyükkaya
China-Nexus Nation State Actors Exploit SAP NetWeaver (CVE-2025-31324) to Target Critical Infrastructures
KrustyLoader SNOWLIGHT VShell CL-STA-0048
2025-04-15 ⋅ sysdig ⋅ Alessandra Rizzo
UNC5174’s evolution in China’s ongoing cyber warfare: From SNOWLIGHT to VShell
SNOWLIGHT Sliver VShell
2024-03-22 ⋅ RH-ISAC ⋅ Lee Clark
Chinese Threat Group UNC5174 Reportedly Exploiting F5 BIG-IP and ScreenConnect CVEs for Active Exploitation
GOREVERSE SNOWLIGHT Sliver UNC5174
2024-03-21 ⋅ Mandiant ⋅ Adam Aprahamian, Austin Larsen, Dan Kelly, Marcin Siedlarz, Mathew Potaczek, Michael Raggi
Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect
GOREVERSE SNOWLIGHT
2024-03-21 ⋅ Mandiant ⋅ Adam Aprahamian, Austin Larsen, Dan Kelly, Marcin Siedlarz, Mathew Potaczek, Michael Raggi
Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect
GOREVERSE SNOWLIGHT Sliver UNC5174

There is no Yara-Signature yet.