Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

A fake resume invoked China's defence-tech elite, then installed VShell

0
Medium
Published: 08/28/2026 (08/28/2026, 15:13:40 UTC)
Source: AlienVault OTX General

Description

A Chinese-language executable disguised as a resume claiming to be from a Beijing Institute of Technology graduate student delivers SNOWLIGHT and VShell RAT. The infection chain uses a custom Go loader with sandbox detection, CPU checks, and sleep-timer evasion before downloading a legitimate DOCX decoy. It then executes a 1,454-byte SNOWLIGHT stager that connects to infrastructure, downloads 4.65 MB of data, XOR-decodes it with key 0x99, and launches a fileless VShell RAT. The lure targets mainland Chinese academics in electrical engineering, power systems, or AI research, providing operators with command execution, file access, screen capture, and lateral movement capabilities. The delivery uses panel-generated SNOWLIGHT components now widely available in cracked VShell releases, making actor-level attribution unreliable beyond identifying an unattributed operator using commodity tooling with China-oriented academic targeting.

Technical Details

Author
AlienVault
Tlp
white
References
["https://blog.himanshuanand.com/2026/08/a-fake-resume-invoked-chinas-defence-tech-elite-then-installed-vshell"]
Adversary
null
Pulse Id
6a91a5a487efed140546d754
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip38.207.178.192

Hash

ValueDescriptionCopy
hashc25d4412f7f93e7de5b2aaf41747175d94cffd983ca20efbd0efcdd718b58c4d
hash81c51138d5527ca7dcc258171eb36659c479f66c86a8947b6340d040b3860a30
hasha7cc7e3cdd2f0f9210044911a483fa5d
hashf6d4da5afc89bf9e536a9002c4d256c696df2389d77279f4c5daf6979557e74e
hash0524619d2471d77aba4b7993f5ffbaa4b8be6d2c0d91e63a02943851dc4b6404
hashed2eaa6ef3eda95383b6efc35b88acbca742ad7bd118931f74727a3139ff7e97
hashc666ac4f1a1b8df7ccfe8b19705279acd8b7eb7a4d0b3802bb3465064883ab25
hashde3f56d0d5b71f2a1a1905f0b01b84fbab237e9d4c5179a05b127d806823f83c

Url

ValueDescriptionCopy
urlhttp://38.207.178.192:50813/EasyConnectUpdata_Log.txt
urlhttp://38.207.178.192:50813/MySQL_LOG.txt

Domain

ValueDescriptionCopy
domaind.d.edsxhbba06.shop
domainoa.muxmyee520.shop
domainpan.qlam.cc
domainv.n.1.xcwanmei09.shop
domainwww.qlam.cc

Threat ID: 6a91c3c7acd9273b49224655

Added to database: 08/28/2026, 17:22:15 UTC

Last updated: 08/28/2026, 18:07:38 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses