TI Mindmap HUB
Threat Intelligence Report

Tracing SNOWLIGHT: A China-Nexus Campaign Against Government Infrastructure

📅 August 9, 2026 📰 socradar.io 🔍 7 CVE(s) referenced

A China-linked threat group leveraged a sophisticated, automated attack infrastructure—centered around the SNOWLIGHT malware family and a cracked Chinese Cobalt Strike variant—to mass-exploit government and commercial targets in over 100 countries, achieving high-impact endpoint compromises via weaponized CVEs and advanced obfuscation tactics.

vendor
CVE-2026-34486, CVE-2026-44262, CVE-2025-24813, CVE-2022-26134, CVE-2021-26855, CVE-2026-21962, CVE-2026-41940

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle