SNOWLIGHT

Malware type
dropper
Last IoC activity
2026-05-27 17:01:19
Profile updated
2026-07-07 13:16:40

Targeted industries: government-and-public-sector defense-and-aerospace

Context

According to sysdig, SNOWLIGHT is used as a dropper for its fileless payload (vshell).

Exploited vulnerabilities

  • CVE-2025-31324 (vulnerability)
  • CVE-2025-55182 (vulnerability)

Reports & references

  • blog.eclecticiq.com — China Nexus Nation State Actors Exploit Sap Netweaver Cve 2025 31324 To Target Critical Infrastructures (report)
  • cloud.google.com — Threat Actors Exploit React2Shell Cve 2025 55182 (report)
  • cloud.google.com — Initial Access Brokers Exploit F5 Screenconnect (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Snowlight (report)
  • sysdig.com — Unc5174 Chinese Threat Actor Vshell (report)

External references