SNOWLIGHT Malware Campaign Exposed by Open Directories

Global map illustrating the SNOWLIGHT malware cyberespionage campaign targets

The operators behind a massive, globally coordinated hacking campaign committed a fatal operational security error. They inadvertently left directories entirely open on the centralized server utilized to prepare and execute their attacks. Consequently, SOCRadar researchers discovered comprehensive target lists, sophisticated exploits, and malicious payloads. Furthermore, they unearthed detailed command execution logs and specialized traffic obfuscation tools. These meticulously maintained records span six critical weeks. Ultimately, they confirm relentless attack attempts and successful compromises of governmental and commercial systems across more than 100 nations.

Extensive file analysis subsequently identified the overarching threat as the SNOWLIGHT malware family. The Google Threat Intelligence Group has tracked SNOWLIGHT payload downloaders meticulously since 2024. Analysts firmly associate this specific malware family with the notorious initial access brokers UNC5174 and UNC6586. Participants within these specialized syndicates systematically breach organizations solely to sell the acquired access to secondary operators.

Global Targeting and Automated Exploitation

The exposed reconnaissance databases contained over 9,990 hostnames distributed across 104 distinct national top-level domains. Strikingly, over 85 percent of these targeted addresses belonged directly to critical government infrastructure. The sprawling victim list included organizations situated in Taiwan, Colombia, China, Brazil, Indonesia, Nigeria, the Philippines, and more than 90 additional territories.

In their executive summary, SOCRadar references 107 successfully compromised nodes. However, their detailed technical table lists 105 independently verified breaches. The SNOWLIGHT Chinese government campaign report does not explicitly explain this minor numerical discrepancy.

Taiwan emerged unequivocally as the primary, high-priority target. The operators systematically aggregated addresses belonging to state institutions, vital healthcare organizations, and educational resources. Subsequently, they launched aggressive assaults against Apache Tomcat servers utilizing CVE-2025-24813 and CVE-2026-34486. The recovered command history documented the simultaneous execution of a single exploit against 37 Taiwanese servers.

The attackers wielded a formidable arsenal containing nine actively exploited vulnerabilities alongside 11 distinct exploitation chains. These weapons specifically targeted Apache Tomcat, Microsoft Exchange, cPanel and WHM, Atlassian Confluence, Laravel, Apache Struts2, and F5 BIG-IP. Notably, the vast majority of these tools derived directly from publicly available proof-of-concept exploits hosted on GitHub.

Severe Compromises and Attributor Evidence

The attack leveraging CVE-2026-41940 against cPanel and WHM inflicted the most catastrophic damage. The adversaries successfully secured root privileges across 16 critical servers. Subsequently, they established interactive command shells and forged persistent, highly privileged administrative tokens. Similarly, the devastating ProxyShell assault against Microsoft Exchange culminated in the outright theft of an NTLM token belonging to a Domain Admin account.

Furthermore, 80 Atlassian Confluence servers involuntarily executed the ‘whoami’ command via CVE-2022-26134. The operators also firmly implanted five discrete web shells on compromised Tomcat servers. They verified remote code execution on two additional systems and successfully identified one highly vulnerable WebLogic server. Conversely, extensive scanning against Laravel and Apache Struts2 installations yielded no definitive signs of successful penetration.

Crucially, this campaign relied heavily on indiscriminate, automated mass scanning rather than meticulously prepared, targeted attacks against specific organizations. Automated scripts indiscriminately probed internet-facing servers, identified installed software versions, deployed applicable exploits, and verified command execution. The attackers found evidence of successful exploitation on roughly one out of every 90 scanned systems.

A Linux-based server operating at 130.94.17[.]180 functioned as the primary operational node. From this centralized hub, operators scanned the global internet, launched exploits, stored critical files, and received incoming connections from infected devices. A secondary server located at 130.94.30[.]168 handled the widespread distribution of SNOWLIGHT components.

Command, Control, and Traffic Obfuscation

To assert absolute control over the compromised systems, the attackers utilized GoCobaltStrike, a sophisticated Chinese-language implementation of Cobalt Strike written in Go. The operators aggressively disabled all licensing restrictions, installing a pirated version boasting a 10-year license and an immense 9,999 client limit. Supplementary modules facilitated extensive credential harvesting, deep domain infrastructure mapping, antivirus evasion, and robust system persistence.

To effectively camouflage their extensive network footprint, the adversaries deployed Neo-reGeorg layered over previously injected JSP web shells. Consequently, the captured servers transformed into covert reverse tunnels, seamlessly redirecting the malicious traffic. These strategically positioned intermediate nodes successfully obscured the direct communication link between the final victims and the primary campaign infrastructure.

Multiple compelling indicators point directly toward operators based in China. The command execution history, the GoCobaltStrike graphical interface, and embedded code comments frequently utilized simplified Chinese characters. The servers actively queried Aliyun and China Telecom DNS services, and critical packages were downloaded directly from an Aliyun mirror.

Furthermore, two specific IP addresses utilized to access the control panel and retrieve malicious files belonged to China Unicom in Tianjin. Astonishingly, all 22 verified GoCobaltStrike logins originated from a single address. The session timestamps perfectly aligned with the UTC+8 time zone. While SOCRadar confidently attributes this campaign to Chinese-speaking operators, they stop short of naming a specific state agency or known APT group.

The Mechanics of SNOWLIGHT Deployment

SNOWLIGHT operated seamlessly across both Linux and Windows environments. The Linux downloader initially identified the precise CPU architecture. Next, it retrieved the appropriate file version and established a connection with the command server. The subsequent malicious module underwent decryption utilizing the static key 0x99. It then executed entirely within memory, completely avoiding writing a conventional executable file to the physical disk.

Once active, the malicious process masqueraded as a legitimate system kernel thread bearing the name “[kworker/0:2]”. Conversely, the Windows variant utilized the built-in certutil.exe utility to download files. It dynamically resolved essential system functions and employed the identical 0x99 decryption key. Overall, the fundamental operational framework of the downloaders remained consistent across both platforms.

The supporting infrastructure maintained at least three distinct data transmission modes, designated internally as tcp, ws, and kcp. Curiously, the “ws” mode did not establish a genuine WebSocket connection. Instead, it transmitted a standard HTTP request disguised with an outdated Firefox 48 user-agent string. These diverse communication variations significantly helped alter the malware’s overall network signature.

Interestingly, the analyzed downloaders incorporated a rudimentary emergency kill switch mechanism. The mere presence of a file named “/tmp/log_de.log” immediately forced the Linux version to terminate its process before attempting to contact the command server. The Windows build similarly searched for “log_de.log” within the designated system temporary folder. While SOCRadar recommends utilizing this marker as a temporary defensive measure, they heavily emphasize the absolute necessity of patching vulnerable software and conducting thorough server audits.

Finally, the domains google.chromeupgrades.com and speedtest.qqmail.website were directly linked to the primary SNOWLIGHT distribution server. The first address deceptively mimicked the official Google Chrome update service, while the second closely resembled the legitimate Tencent QQ Mail infrastructure. These deceptive naming conventions likely assisted in camouflaging the malicious traffic as benign requests to familiar, trusted services.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply