SOCRadar Uncovers New China-Nexus Campaign SNOWLIGHT Against Government Infrastructure

The SOCRadar Threat Research Unit (STRU) has identified and analyzed an exposed adversary-operated staging server containing a full attack infrastructure: reconnaissance lists, 9 weaponized CVEs, a cracked Chinese version of Cobalt-Strike C2 (GoCobaltStrike / “GOCS”), a Metasploit Framework install, tunneling tooling, and payload-hosting infrastructure.

The artifacts span a six-week operational window and provide direct evidence of both attempted and successful compromise against government and commercial infrastructureacross more than 100 countries

Further analysis of the retrieved malware revealed a match with the SNOWLIGHT malware family, a family tracked by the Google Threat Intelligence Group (GTIG) and associated with China-nexus access brokers UNC5174/UNC6586.

Key Findings

  • Attribution to China-Nexus Actors: The core delivery mechanisms have been definitively linked to the SNOWLIGHT malware family. Tracked by the Google Threat Intelligence Group since 2024, identified loaders are heavily associated with China-nexus access brokers UNC5174 and UNC6586.
  • Cracked Chinese Reimplementation of Cobalt Strike C2 Infrastructure: Command and control (C2) infrastructure is managed via “GoCobaltStrike,” a specialized Chinese-language reimplementation of Cobalt Strike authored by the handle “星落”, featuring cracked license constraints.
  • Government Sector Prioritization: More than 85% of mapped reconnaissance listings target national infrastructure, resolving to second-level government domains (.gov.*.go.id) across Taiwan, Colombia, China, Brazil, Indonesia, Nigeria, the Philippines, and over 90 other geographical jurisdictions.
  • High-Impact Endpoint Takeovers: Out of an expansive footprint exceeding 9,990 hostnames across 104 country-code TLDs (top-level domain), the threat actors successfully exploited 9 distinct CVEs to breach 107 endpoints. This includes critical administrative compromises: 16 root-level cPanel/WHM takeovers (CVE-2026-41940) and 1 Domain Admin level compromise via ProxyShell.
  • Reverse Tunnel Traffic Obfuscation: Operators effectively masked their network trail by deploying Neo-reGeorg web shells over pre-existing JSP shell implants, using third-party compromised systems as reverse tunnels to proxy further malicious actions.
  • Opportunistic “Spray-and-Check” Tactical Model: The campaign leverages automated scanning rather than bespoke targeting. Roughly 1 out of every 90 scanned targets resulted in a Remote Code Execution (RCE) oracle hit, credential theft, or shell validation.

To view the full research, please see Tracing SNOWLIGHT: A China-Nexus Campaign Against Government Infrastructure

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading