Summary
Michel and Patrick from NVISO present VShell as a Chinese-language post-exploitation command-and-control framework used in real incident-response cases, and the value proposition of the talk is practical: understand what VShell is, how its infrastructure can be tracked on the internet, and why defenders should focus on both vulnerable entry points and C2 fingerprinting. They explain that their research began with multiple client compromises, where investigation leads pointed toward VShell. A CSBN report connected the framework to a Chinese state-sponsored threat actor referred to as UNC 5174, and NVISO then sought to understand the tooling in more depth by locating a copy of the deleted GitHub distribution through an archived online source.
Key Topics
5 key topics from Patrick Lodder and Michel Coene at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Patch known exploited vulnerabilities before attackers deploy post-exploitation frameworks.
- Combine passive fingerprints to reduce noisy C2 infrastructure leads.
- Inspect authenticated endpoints, not only default web pages.
- Treat proxy-capable backdoors as direct internal-network access risks.
- Use internet scan datasets before running risky active scans.
“once something comes on the internet, it never goes away.”
Up Next


Next in agenda
What Insider Risk Teaches Us About Securing Agentic AI

Also on cybersecurity
A Pragmatic Path to Continuous Purple Teaming
Cas van Cooten


Also on incident response
