A fake resume invoked China's defence-tech elite, then installed VShell
A Chinese-language executable disguised as a resume claiming to be from a Beijing Institute of Technology graduate student delivers SNOWLIGHT and VShell RAT. The infection chain uses a custom Go loader with sandbox detection, CPU checks, and sleep-timer evasion before downloading a legitimate DOCX decoy. It then executes a 1,454-byte SNOWLIGHT stager that connects to infrastructure, downloads 4.65 MB of data, XOR-decodes it with key 0x99, and launches a fileless VShell RAT. The lure targets mainland Chinese academics in electrical engineering, power systems, or AI research, providing operators with command execution, file access, screen capture, and lateral movement capabilities. The delivery uses panel-generated SNOWLIGHT components now widely available in cracked VShell releases, making actor-level attribution unreliable beyond identifying an unattributed operator using commodity tooling with China-oriented academic targeting.
Indicators of Compromise
- ip: 38.207.178.192
- hash: c25d4412f7f93e7de5b2aaf41747175d94cffd983ca20efbd0efcdd718b58c4d
- hash: 81c51138d5527ca7dcc258171eb36659c479f66c86a8947b6340d040b3860a30
- hash: a7cc7e3cdd2f0f9210044911a483fa5d
- hash: f6d4da5afc89bf9e536a9002c4d256c696df2389d77279f4c5daf6979557e74e
- hash: 0524619d2471d77aba4b7993f5ffbaa4b8be6d2c0d91e63a02943851dc4b6404
- hash: ed2eaa6ef3eda95383b6efc35b88acbca742ad7bd118931f74727a3139ff7e97
- hash: c666ac4f1a1b8df7ccfe8b19705279acd8b7eb7a4d0b3802bb3465064883ab25
- hash: de3f56d0d5b71f2a1a1905f0b01b84fbab237e9d4c5179a05b127d806823f83c
- url: http://38.207.178.192:50813/EasyConnectUpdata_Log.txt
- url: http://38.207.178.192:50813/MySQL_LOG.txt
- domain: d.d.edsxhbba06.shop
- domain: oa.muxmyee520.shop
- domain: pan.qlam.cc
- domain: v.n.1.xcwanmei09.shop
- domain: www.qlam.cc
A fake resume invoked China's defence-tech elite, then installed VShell
Description
A Chinese-language executable disguised as a resume claiming to be from a Beijing Institute of Technology graduate student delivers SNOWLIGHT and VShell RAT. The infection chain uses a custom Go loader with sandbox detection, CPU checks, and sleep-timer evasion before downloading a legitimate DOCX decoy. It then executes a 1,454-byte SNOWLIGHT stager that connects to infrastructure, downloads 4.65 MB of data, XOR-decodes it with key 0x99, and launches a fileless VShell RAT. The lure targets mainland Chinese academics in electrical engineering, power systems, or AI research, providing operators with command execution, file access, screen capture, and lateral movement capabilities. The delivery uses panel-generated SNOWLIGHT components now widely available in cracked VShell releases, making actor-level attribution unreliable beyond identifying an unattributed operator using commodity tooling with China-oriented academic targeting.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://blog.himanshuanand.com/2026/08/a-fake-resume-invoked-chinas-defence-tech-elite-then-installed-vshell"]
- Adversary
- null
- Pulse Id
- 6a91a5a487efed140546d754
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip38.207.178.192 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashc25d4412f7f93e7de5b2aaf41747175d94cffd983ca20efbd0efcdd718b58c4d | — | |
hash81c51138d5527ca7dcc258171eb36659c479f66c86a8947b6340d040b3860a30 | — | |
hasha7cc7e3cdd2f0f9210044911a483fa5d | — | |
hashf6d4da5afc89bf9e536a9002c4d256c696df2389d77279f4c5daf6979557e74e | — | |
hash0524619d2471d77aba4b7993f5ffbaa4b8be6d2c0d91e63a02943851dc4b6404 | — | |
hashed2eaa6ef3eda95383b6efc35b88acbca742ad7bd118931f74727a3139ff7e97 | — | |
hashc666ac4f1a1b8df7ccfe8b19705279acd8b7eb7a4d0b3802bb3465064883ab25 | — | |
hashde3f56d0d5b71f2a1a1905f0b01b84fbab237e9d4c5179a05b127d806823f83c | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://38.207.178.192:50813/EasyConnectUpdata_Log.txt | — | |
urlhttp://38.207.178.192:50813/MySQL_LOG.txt | — |
Domain
| Value | Description | Copy |
|---|---|---|
domaind.d.edsxhbba06.shop | — | |
domainoa.muxmyee520.shop | — | |
domainpan.qlam.cc | — | |
domainv.n.1.xcwanmei09.shop | — | |
domainwww.qlam.cc | — |
Threat ID: 6a91c3c7acd9273b49224655
Added to database: 08/28/2026, 17:22:15 UTC
Last updated: 08/28/2026, 18:07:38 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.