SNOWLIGHT
- Malware type
- dropper
- Last IoC activity
- 2026-05-27 17:01:19
- Profile updated
- 2026-07-07 13:16:40
Targeted industries: government-and-public-sector defense-and-aerospace
Context
According to sysdig, SNOWLIGHT is used as a dropper for its fileless payload (vshell).
Exploited vulnerabilities
- CVE-2025-31324 (vulnerability)
- CVE-2025-55182 (vulnerability)
Reports & references
- blog.eclecticiq.com — China Nexus Nation State Actors Exploit Sap Netweaver Cve 2025 31324 To Target Critical Infrastructures (report)
- cloud.google.com — Threat Actors Exploit React2Shell Cve 2025 55182 (report)
- cloud.google.com — Initial Access Brokers Exploit F5 Screenconnect (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Snowlight (report)
- sysdig.com — Unc5174 Chinese Threat Actor Vshell (report)