Loading summary
Dave Bittner
You're listening to the Cyberwire network powered by N2K. And now a message from Blackcloak. Did you know the easiest way for cybercriminals to bypass your company's defenses is by targeting your executives and their families at home? Blackcloak's award winning digital executive protection platform secures their personal devices, home networks and connected lives. Because when executives are compromised at home, your company is at risk. In fact, over one third of new members discover they've already been breached. Protect your executives and their families 24 7, 365 with Black Cloak. Learn more at BlackCloak IO. Hello everyone and welcome to the Cyberwires Research Saturday. I'm Dave and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities, solving some of the hard problems and protecting ourselves in our rapidly evolving cyberspace. Thanks for joining us.
Crystal Morin
This threat actor was identified by Google's Mandiant threat Group about a year ago. The interesting thing about this threat actor is they are not the typical Chinese nation state apt like you expect. They're not a government sponsored entity. We believe from the way that this actor is behaving and from what Mandian has said in their previous reporting that this is an individual or possibly multiple. But as of right now, it's a person who is contracted by the Chinese government to support their cyber war efforts.
Dave Bittner
That's Crystal Morin, CyberSecurity Strategist from Sysdig. The research we're discussing today is titled UNC5174's Evolution in China's Ongoing Cyber Warfare from Snowlight to V Shell.
Crystal Morin
Not someone who works for the government, he's just his own independent person. They perhaps reached out to this person and said, hey, we've seen what you're doing online. You're really great. Do you want to come and work for us and support our efforts? So he was contracted into the Chinese government and I'm saying he. But we don't know that that's for certain. So that's how this person is operating right now. Completely independent, can do their own work on the side as well. But this particular campaign is on behalf of the Chinese government. However, what we saw that was also very interesting. So in the report we said that the motivations for this report or for this campaign rather were for espionage, but also possibly for reselling access. And those are two very different motivations that you don't normally see from one threat actor in one campaign. So the reason that we think this is happening again is attributing it to the reason that this threat actor is a contractor. So when they get an initial access into a victim environment and they exfiltrate data and do what they need to do, go to the Chinese government and say, hey, look at all this cool information that we stole from this particular entity. Here you go. And they either take it or the government says, oh, we don't really care about them. Thanks, but no thanks, we don't want it. So then this threat actor can potentially take that information and turn around and sell it. Well, I already have access to this victim. I did all of the hard work. The government's not going to pay me. Somebody else might pay me for access. So I think that's where we're seeing those two different motivations for why we're seeing this data. Ax fell. And these victims go two different ways in this campaign right now.
Dave Bittner
Yeah. So perhaps a double dipping mercenary, if you will. Absolutely, yeah. Interesting. Well, describe for us, for folks who aren't familiar, what is vshell and how does it compare to some of the other remote access tools that are out there?
Crystal Morin
Okay, so vshell is a fairly advanced open source tool. It's relatively new as well. I believe it just came out in 2024 in the open source world on GitHub. It allows for persistent access, command execution, data ax filtration, like a lot of rats, allow all kinds of different capabilities within your attack spectrum. Vshell for this particular actor allowed a lot of stealth, like I said, the persistence for just prolonged access to these compromised networks. We saw vshell pop up in Chinese underground channels on the Dark Web. That's where they were talking about it. Vshell was created by a Chinese speaking developer, which is why we saw it in those channels. And the developer actually abandoned it and removed v shell from GitHub and from the web, tried to take down as much of the code as he could for legal reasons because it started being used right away, like many other open source tools for malicious purposes shortly after he released it to the public. Its original intent was for a red team security tool. There's a lot of incredibly intelligent developers all over the world that create these fascinating red team tools that are really, really useful for defenders to work through their environments and look for weaknesses, look for vulnerabilities, they're really useful. But when they're published on GitHub, you're not just sharing those tools with good guys, the bad guys can find them too. So that's what happened in this case. The developer took it down, but obviously it was shared quite a bit. Folks already had the code from when he did initially upload it. So the binaries for Vshal were already in Telegram channels and they were leaked out toward the end of 2024. Some of the whisperings were China, quote unquote leaked it. But we don't know what that means. Right, everybody. A lot of the folks using Vishell were Chinese speaking. So was it Chinese government that leaked B shell after the developer shut it down? We don't know. One of the other really fascinating aspects of vshell that he worked into this RAT is that it's fileless. So fileless execution, again stealth means that the code can be executed without residing on a disk or as a file binary. So it makes it very again, difficult to find. It's really easy for users to obfuscate. And then in conjunction with Vshell, this threat actor used WebSockets for C2 to then obtain the data that they were exfilling from victim environments to send those payloads encrypted that they were picking up with the vshell.
Dave Bittner
One of the things that your research highlights is the use of Snowlight malware in this attack chain. Can you describe for us what that is and what part it played?
Crystal Morin
Yes. So Snowlight is a custom malware which we're very used to seeing from advanced threat groups, right? So this is a contractor working on behalf of the Chinese government. So we're going to consider this threat actor advanced, very knowledgeable and very capable in offensive cyber. So this threat actor has developed this custom malware. So anytime we see the use of Snow Light, we can safely assume that it's probably being used by UNC5174. It's not code that is accessible open source. It's only going to be available to that particular threat actor. So that's one of the reasons that we know it's this threat actor and we were able to attribute this entire campaign to this person. This campaign was interesting in that custom malware has a binary, right? That's how in threat intelligence, often when we're writing IOC based detections, you take the MD5 hash, right? You can just throw that into a detection and if you trigger, it's easy. You're like, okay, something bad's happening over here. For malware and custom malware like this, it's not easy to change the binary like it is with a file hash. For a hash related to just a file of a script, you can change the file name and the hash changes that's associated with it. The Binaries for malware. You have to actually make modifications to your malware scripts. And that takes time and effort. So in this campaign we identified 40 different binaries so far associated with Snowlight. We can see that this is very clearly Snowlight malware. It performs the same, same, it looks the same, but every deployment of the malware is slightly different. So every victim that's breached by this malware, if they just have these IOC based detection set up based on other victims who may be seeing snow light, they're not necessarily going to see this activity happening. Because this threat actor is changing his malware ever so slightly every time he enters a victim environment. That was fascinating to see that that is very advanced capability and a pain that takes a lot of effort. So.
Dave Bittner
Right, right.
Crystal Morin
It's a lot of work. Yeah.
Dave Bittner
Yeah. We'll be right back. Secure access is crucial for US public sector missions. Ensuring that only authorized users can access certain systems, networks or data. Are your defenses ready? Cisco's security service Edge delivers comprehensive protection for your network and users. Experience the power of zero trust and secure your workforce force wherever they are. Elevate your security Strategy by visiting Cisco.com Go SSE that's Cisco.com Go SSE. Bad actors don't break in, they log in. Attackers use stolen credentials in nearly nine out of 10 data breaches. Once inside, they're after one thing, your data. Varonis AI powered data security platform secures your data at scale across las SaaS and hybrid cloud environments. Join thousands of organizations who trust Varonis to keep their data safe. Get a free data risk assessment@varonis.com well, what types of organizations is this threat actor targeting here?
Crystal Morin
So this particular threat actor, we're seeing them target government agencies, educational institutions, non governmental organizations, research facilities. This is mostly in the west, US and allies in Europe, and then a handful of organizations in Asia as well. Strategically concerning China and their adversaries in apac.
Dave Bittner
What are your recommendations then for organizations to defend themselves? I mean, I'm thinking both against this specifically, but also this kind of thing.
Crystal Morin
Well, so in the end of our report that we put out, our threat research team actually wrote a detection analytic to be able to capture the behaviors associated with V shell. So like I said, with any type of advanced threat or this kind of behavior, they take the time to evade defenses. They don't want to be captured. It's not easy to find them. So you need to look for their behavior. And multiple things chain together. Right. You can't just alert on IOCs. So our threat research team wrote A detection analytic that is open source. So it's not just for our customers, it's for everyone to be able to capture some of the behaviors that we noticed with vshell deployment. So if vshell is deployed in your environment, then this detection alert should trigger for you and then that would obviously initiate an investigation to see and this again, vshell is an open source tool. Just because you see Vishal in your environment doesn't mean you're being attacked by a nation state threat actor. It could just be your red team conducting something, an operation. So it just requires some look into that activity, just as anything else would. But if you fall within that geographical focus and you're in that targeted sector, you know, your organization is a target of China and you see something like this in your environment, then that would definitely require some further investigation.
Dave Bittner
Well, you mentioned earlier that there's a certain amount of sophistication here from, from this actor. I mean, how would you rate them as you look at the, the various, you know, groups you've been tracking? Is this more sophisticated than average?
Crystal Morin
In my personal opinion, Yes, I would say so. I think this threat actor definitely took some steps to up their game. This is the ttps that they chose to employ in this campaign were incredibly intentional. Snow White malware is a custom malware that takes time and effort to develop something like that. This V Shell RAT malware is open source, which is just convenient, but it is a very capable tool as well. But then like I said, that WebSocket C2 is pretty uncommon. So this threat actor is really thin thinking through from beginning to end of campaign. And yes, I would say fairly well advanced as opposed to some other threat groups. I mean we could definitely. He's state sponsored. So this isn't just a regular cyber criminal. This isn't a ransomware group. This isn't just luck. Everything that this threat actor is doing is intentional. And the capabilities of this campaign definitely show that.
Dave Bittner
What about persistence? I mean, if someone discovers that they have an issue here and they go to remove it, are there things that the threat actors put in place to be able to stick around?
Crystal Morin
The vshell malware is supposed to allow the threat actor persistence. Unfortunately, with these campaigns we have yet to identify what the initial access vector was. So if you have been a target of UNC5174 and you are seeing Snowlight malware and you're seeing V shell in your environment, obviously that's definitely going to trigger a much larger investigation. And it could have started with spear phishing campaign Right. Stolen credentials. If there's a vulnerability, a misconfiguration, I don't know. So if you're able to remove the malware from your system when you find it, that's great. But if you're not able to trace back to how the threat actor got into your environment, then they're just going to let themselves back in. So like I said, in this case, unfortunately, we don't know how they're getting into the environments right now. But typically from, I mean, all of the reporting that we're seeing, it's usually done in pretty similar fashion across the board. So you look for those typical initial access vectors and remediate those issues.
Dave Bittner
Does the fact that it's fileless, as you mentioned, does that add extra complications?
Crystal Morin
It makes it difficult to track because there's no code execution that exists. Again, it makes it harder to just write simple detection analytics to capture behavior happening in your environment. So that's just the challenging aspect of it. If you don't, you don't know that this is happening, you don't know what to look for, then you're never going to alert on this kind of behavior. But if you're staying up on threat intelligence and you're reading these kinds of reports, sharing with your friends and ISACs and things like that, then that's how you can mitigate this from happening in the future.
Dave Bittner
Our thanks to Crystal Morin from Sysdig for joining us. The research is titled UNC5174's Evolution in China's Ongoing Cyber Warfare from Snowlight to V Shell. We'll have a link in the show notes and that's Research Saturday, brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com this episode was produced by Liz Stokes, were mixed by Elliot Teltzman and Trey Hester. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher and I'm Dave Bittner. Thanks for listening. We'll see you back here next time.
CyberWire Daily – Detailed Summary of "China’s New Cyber Arsenal Revealed" [Research Saturday]
Release Date: April 26, 2025
Host: Dave Bittner
Guest: Crystal Morin, CyberSecurity Strategist from Sysdig
Research Focus: UNC5174's Evolution in China's Ongoing Cyber Warfare from Snowlight to V Shell
In the April 26, 2025 episode of CyberWire Daily, hosted by Dave Bittner from N2K Networks, the focus is on unveiling China’s evolving cyber capabilities. Titled "China’s New Cyber Arsenal Revealed", this episode delves deep into the research conducted by Crystal Morin from Sysdig, spotlighting the threat actor group UNC5174 and their utilization of sophisticated tools like Snowlight and V Shell in ongoing cyber warfare efforts.
At the outset, Crystal Morin provides an insightful analysis of the threat actor identified by Google's Mandiant Threat Group.
Crystal Morin [01:23]: "This threat actor was identified by Google's Mandiant threat Group about a year ago. The interesting thing about this threat actor is they are not the typical Chinese nation state APT like you expect. They're not a government-sponsored entity."
Contrary to typical state-sponsored Advanced Persistent Threats (APTs), UNC5174 appears to operate independently or as a contractor for the Chinese government. Crystal elaborates:
Crystal Morin [02:33]: "Not someone who works for the government, he's just his own independent person. They perhaps reached out to this person and said, hey, we've seen what you're doing online. You're really great. Do you want to come and work for us and support our efforts?"
This dual motivation—espionage and reselling access—sets UNC5174 apart, indicating a "double-dipping mercenary" approach where the actor serves both the Chinese government's interests and personal profiteering.
A significant portion of the discussion centers on V Shell, an advanced open-source Remote Access Tool (RAT) utilized by UNC5174.
Crystal Morin [04:57]: "Vshell is a fairly advanced open source tool... It allows for persistent access, command execution, data exfiltration... Vshell for this particular actor allowed a lot of stealth, the persistence for just prolonged access to these compromised networks."
Originally developed as a red team security tool, V Shell became a weapon when leaked to underground channels:
Crystal Morin [04:57]: "The developer actually abandoned it and removed V Shell from GitHub and from the web... but the binaries for V Shell were already in Telegram channels and they were leaked out toward the end of 2024."
Key features of V Shell include fileless execution and the use of WebSockets for Command and Control (C2), enhancing its stealth and making detection more challenging.
Another critical component discussed is Snowlight, customized malware integral to UNC5174's operations.
Crystal Morin [08:49]: "Snowlight is a custom malware... anytime we see the use of Snow Light, we can safely assume that it's probably being used by UNC5174."
Unlike open-source tools, Snowlight is unique to UNC5174, making it a reliable indicator of their activities. Its sophistication is evident in the way each deployment is slightly modified, complicating traditional IOC-based detection methods:
Crystal Morin [08:49]: "In this campaign we identified 40 different binaries so far associated with Snowlight... every deployment of the malware is slightly different."
UNC5174's targeting strategy encompasses a diverse range of sectors and geographies:
Crystal Morin [13:41]: "This particular threat actor, we're seeing them target government agencies, educational institutions, non-governmental organizations, research facilities... mostly in the west, US and allies in Europe, and then a handful of organizations in Asia as well."
This broad targeting underscores the strategic intent behind UNC5174's campaigns, aiming to disrupt and extract valuable information from key institutions across multiple regions.
In addressing defenses, Crystal emphasizes the importance of behavior-based detection over traditional IOC methods:
Crystal Morin [14:23]: "Our threat research team wrote a detection analytic that is open source... if V Shell is deployed in your environment, then this detection alert should trigger for you."
She advises organizations to look for chained behaviors and engage in comprehensive investigations upon detecting indicators like V Shell, especially if they fall within the geographical focus or are part of targeted sectors.
Crystal Morin rates UNC5174 as a highly sophisticated threat actor:
Crystal Morin [16:44]: "I would say this threat actor definitely took some steps to up their game... Snow White malware is a custom malware... the WebSocket C2 is pretty uncommon... they're really thin thinking through from beginning to end of campaign."
This level of sophistication indicates a well-resourced and highly capable group, differentiating them from typical cybercriminal entities or less advanced threat groups.
The use of fileless malware like V Shell poses significant challenges for detection and removal:
Crystal Morin [19:55]: "It makes it difficult to track because there's no code execution that exists... it's harder to just write simple detection analytics to capture behavior happening in your environment."
Moreover, without identifying the initial access vector, remediating the threat becomes arduous, as the actors can potentially regain entry through the same vulnerabilities.
Crystal concludes by reiterating the necessity for organizations to stay informed through threat intelligence, engage with Information Sharing and Analysis Centers (ISACs), and implement comprehensive detection strategies that focus on behavior rather than solely on static indicators.
Crystal Morin [20:58]: "If you're staying up on threat intelligence and you're reading these kinds of reports, sharing with your friends and ISACs and things like that, then that's how you can mitigate this from happening in the future."
This comprehensive summary encapsulates the critical discussions and insights shared during the episode, providing a clear understanding of the evolving cyber threats posed by China’s new cyber arsenal as revealed in Sysdig's research.