Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Have a Fast and Furious Father’s Day

Parents who track adult children should back off

Post Malone dedicates Toronto concert to Oliver Tree

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Chinese hackers target Linux systems using Snowlight malware and VShell tools
Celebrities

Chinese hackers target Linux systems using Snowlight malware and VShell tools

By April 15, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 15, 2025Ravi LakshmananLinux/Malware

Chinese hackers target Linux

The China-related threat actor, known as UNC5174, is attributed to a new campaign that leverages a known malware variant called snow light and a new open source tool called VSHELL that infects Linux systems.

“Threat actors use open source tools in their armory for cost-effectiveness and obfuscation, in this case they’re more integrated with non-state support, often non-technical pools of enemies.

“This seems particularly true for this particular threat actor who has been under the radar last year since partnering with the Chinese government.”

UNC5174, also known as Uteus (or uetus), was previously recorded by Google-owned Mandiant as leveraging security flaws in Connectwise Screenconnect and F5 Big-IP software. Super shell.

Cybersecurity

Also, the attack was Goreverse, a public reverse shell backdoor written in Golang, which runs on Secure Shell (SSH).

In a 2024 Cyber ​​Threat Summary Report published last month, the French National Agency for Information Systems Security (ANSSI) said it had observed attackers using similar commercial services to weaponize the security flaws of IVANTI Cloud Service Appliance (CSA) Security Fault (CSA) Security Fault (CVE-2024-2024-9380). Get control and execute arbitrary code.

“This moderately refined and modest intrusion set is characterized primarily by the use of intrusion tools available as open source and the use of rootkit codes that have already been reported publicly,” ANSSI said.

Note that the analysis of artifacts uploaded to Virustotal from China in October 2024 shows that both snow light and VShell can target Apple Macos systems, allowing the latter to be distributed as a fake CloudFlare Authenticator application.

In the attack chain observed by Sysdig in late January 2025, Snowlight malware acts as a dropper for a useless, in-memory payload called Vshell, a remote access trojan (rat) widely used by Chinese cybercriminals. The initial access vector used for the attack is currently unknown.

Specifically, initial access is used to run a malicious Bash script (“Download_backd.sh”) that unfolds two binaries related to Snow Light (DNSLOGER) and Sliver (System_Worker).

The final stage of the attack uses specially created requests to the C2 server to provide VShell via snow light, thereby enabling remote control and further post-enhanced exploitation.

“[VShell] According to Rizzo, Rizzo said. Sysdig said it acts as a “remote access trojan), allowing abusers to run any command to download or upload files.

Cybersecurity

This disclosure is because TeamT5 has revealed that China and Nexus hacking groups likely exploited the security flaws in Ivanti appliances (CVE-2025-0282 and CVE-2025-22457) to initially access Spawnchimera Malware.

Taiwan’s cybersecurity company said the attack targeted a number of sectors across nearly 20 countries, including Austria, Australia, France, Spain, Japan, South Korea, the Netherlands, Singapore, Taiwan, the United Arab Emirates, the UK and the US.

The findings also resulted in the US National Security Agency’s launching a “advanced” cyberattack at the Asian Winter Games in February, pointing at the fingers of three NSA agents, bringing repeated attacks on China’s critical information infrastructure and accusations against Howaway.

“In the 9th Asian Winter Game, the US government carried out a cyberattack on the game’s information systems and the key information infrastructure in Edo,” said Lin Jiang, a spokesman for the Ministry of Foreign Affairs. “This move is awful as it seriously puts China’s critical information infrastructure, national defense, fiscal, social, production safety, and the safety of citizens’ personal information.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFrom production to creative event agencies
Next Article Jordan says it will block plots that threaten national security | News

Related Posts

The meaning behind Michelle Obama’s vintage photo skirt

June 17, 2026

Angelina Jolie updates her ‘recession blonde’ look in New York City

June 17, 2026

Duchess Kate goes from butter yellow to marigold at Royal Ascot

June 17, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Have a Fast and Furious Father’s Day

Parents who track adult children should back off

Post Malone dedicates Toronto concert to Oliver Tree

Stand-up comic goes on extensive tour with Frank Sinatra

Trending Posts

Post Malone dedicates Toronto concert to Oliver Tree

June 18, 2026

Stand-up comic goes on extensive tour with Frank Sinatra

June 18, 2026

Police officer Stewart Copeland talks about his relationship with Sting

June 18, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.