Threats Tagged 'snowlight'
View all threats tagged with 'snowlight'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'snowlight'
Click on any threat for detailed analysis and mitigation recommendations
This threat involves a Chinese-language executable disguised as a resume purportedly from a Beijing Institute of Technology graduate student. It delivers SNOWLIGHT and a fileless VShell RAT using a custom Go loader with sandbox evasion techniques. The malware targets mainland Chinese academics in electrical engineering, power systems, or AI research. It provides attackers with command execution, file access, screen capture, and lateral movement capabilities. The infection chain includes downloading a legitimate DOCX decoy and XOR-decoding a payload before launching the RAT. Attribution is unreliable due to the use of widely available cracked VShell components. No patch or fix is indicated. Join the discussion | AlienVault OTX General | 08/28/2026, 15:13:40 UTC Added: 08/28/2026, 17:22:15 UTC |
0 China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators. Join the discussion | CVE Database V5 | 08/03/2026, 09:40:19 UTC Added: 07/21/2025, 17:31:09 UTC |
0 CVE-2025-55182, also known as React2Shell, is a critical pre-authentication remote code execution vulnerability affecting React Server Components and related frameworks. With a CVSS score of 10.0, it allows attackers to execute arbitrary code on vulnerable servers through a single malicious HTTP request. Exploitation has been detected since December 5, 2025, primarily in red team assessments but also in real-world attacks delivering coin miners. The vulnerability stems from a failure to validate incoming payloads in React Server Components, enabling attackers to inject malicious structures leading to prototype pollution and remote code execution. Post-exploitation activities include running reverse shells, achieving persistence, evading security defenses, and attempting lateral movement to cloud resources. Join the discussion | AlienVault OTX General | 12/15/2025, 21:41:54 UTC Added: 12/16/2025, 09:09:37 UTC |
Showing 1 to 3 of 3 results