Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

Israeli attacks on Iran could send oil prices above $100 as tensions rise

Top Startups and High-Tech Funding News – June 12, 2025

Meta AI apps are privacy disasters

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Chinese hackers target Linux systems using Snowlight malware and VShell tools
Identity

Chinese hackers target Linux systems using Snowlight malware and VShell tools

userBy userApril 15, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 15, 2025Ravi LakshmananLinux/Malware

Chinese hackers target Linux

The China-related threat actor, known as UNC5174, is attributed to a new campaign that leverages a known malware variant called snow light and a new open source tool called VSHELL that infects Linux systems.

“Threat actors use open source tools in their armory for cost-effectiveness and obfuscation, in this case they’re more integrated with non-state support, often non-technical pools of enemies.

“This seems particularly true for this particular threat actor who has been under the radar last year since partnering with the Chinese government.”

UNC5174, also known as Uteus (or uetus), was previously recorded by Google-owned Mandiant as leveraging security flaws in Connectwise Screenconnect and F5 Big-IP software. Super shell.

Cybersecurity

Also, the attack was Goreverse, a public reverse shell backdoor written in Golang, which runs on Secure Shell (SSH).

In a 2024 Cyber ​​Threat Summary Report published last month, the French National Agency for Information Systems Security (ANSSI) said it had observed attackers using similar commercial services to weaponize the security flaws of IVANTI Cloud Service Appliance (CSA) Security Fault (CSA) Security Fault (CVE-2024-2024-9380). Get control and execute arbitrary code.

“This moderately refined and modest intrusion set is characterized primarily by the use of intrusion tools available as open source and the use of rootkit codes that have already been reported publicly,” ANSSI said.

Note that the analysis of artifacts uploaded to Virustotal from China in October 2024 shows that both snow light and VShell can target Apple Macos systems, allowing the latter to be distributed as a fake CloudFlare Authenticator application.

In the attack chain observed by Sysdig in late January 2025, Snowlight malware acts as a dropper for a useless, in-memory payload called Vshell, a remote access trojan (rat) widely used by Chinese cybercriminals. The initial access vector used for the attack is currently unknown.

Specifically, initial access is used to run a malicious Bash script (“Download_backd.sh”) that unfolds two binaries related to Snow Light (DNSLOGER) and Sliver (System_Worker).

The final stage of the attack uses specially created requests to the C2 server to provide VShell via snow light, thereby enabling remote control and further post-enhanced exploitation.

“[VShell] According to Rizzo, Rizzo said. Sysdig said it acts as a “remote access trojan), allowing abusers to run any command to download or upload files.

Cybersecurity

This disclosure is because TeamT5 has revealed that China and Nexus hacking groups likely exploited the security flaws in Ivanti appliances (CVE-2025-0282 and CVE-2025-22457) to initially access Spawnchimera Malware.

Taiwan’s cybersecurity company said the attack targeted a number of sectors across nearly 20 countries, including Austria, Australia, France, Spain, Japan, South Korea, the Netherlands, Singapore, Taiwan, the United Arab Emirates, the UK and the US.

The findings also resulted in the US National Security Agency’s launching a “advanced” cyberattack at the Asian Winter Games in February, pointing at the fingers of three NSA agents, bringing repeated attacks on China’s critical information infrastructure and accusations against Howaway.

“In the 9th Asian Winter Game, the US government carried out a cyberattack on the game’s information systems and the key information infrastructure in Edo,” said Lin Jiang, a spokesman for the Ministry of Foreign Affairs. “This move is awful as it seriously puts China’s critical information infrastructure, national defense, fiscal, social, production safety, and the safety of citizens’ personal information.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFrom production to creative event agencies
Next Article Jordan says it will block plots that threaten national security | News
user
  • Website

Related Posts

How Vextrio and Affiliates run a global fraud network

June 12, 2025

New token break attacks bypass AI moderation with text changes for single characters

June 12, 2025

AI agents run on secret accounts – learn how to protect them in this webinar

June 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Israeli attacks on Iran could send oil prices above $100 as tensions rise

Top Startups and High-Tech Funding News – June 12, 2025

Meta AI apps are privacy disasters

Bluesky Backlash misses points

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Top Startups and High-Tech Funding News – June 12, 2025

AI Internet is down: Google Cloud outage breaks Firebase, Supabase, Cursor, Lovable, etc.

Digital banking startup Chime pops with IPO debut, raising $700 million at a valuation of $11.6 billion

Spanish AI Startup Multiverse raises $227 million to reduce LLMS and reduce inference costs by 80%

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.