VShell
- First seen
- 2020-06-01 00:00:00
- Malware type
- rat, backdoor
- Last IoC activity
- 2026-07-22 04:25:04
- Profile updated
- 2026-07-07 13:16:24
Targeted industries: defense-and-aerospace government-and-public-sector technology-and-telecommunications
Context
VShell is an OST framework written in Go, enabling availability of implants for multiple platforms (Windows, Linux, macOS).
Detection coverage
- 1 YARA rules
Exploited vulnerabilities
- CVE-2025-31324 (vulnerability)
Detection rules
- MALPEDIA_Win_Vshell_Auto (yara-rule)
Reports & references
- blog.eclecticiq.com — China Nexus Nation State Actors Exploit Sap Netweaver Cve 2025 31324 To Target Critical Infrastructures (report)
- Trend Micro — Earth Lamia (report)
- sysdig.com — Unc5174 Chinese Threat Actor Vshell (report)
- seqrite.com — Operation Dragonclone Chinese Telecom Veletrix Vshell Malware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Vshell (report)
- github.com — Vshell (report)
- trellix.com — The Silent Fileless Threat Of Vshell (report)
- blog.nviso.eu — Vshell (report)