A fake resume invoked China's defence-tech elite, then installed VShell
Reported 28 Aug 2026 by otx · Severity: medium
A Chinese-language executable disguised as a resume claiming to be from a Beijing Institute of Technology graduate student delivers SNOWLIGHT and VShell RAT. The infection chain uses a custom Go loader with sandbox detection, CPU checks, and sleep-timer evasion before downloading