I've been seeing Vshell in #opendirs for a few years. With the recent attention, it was time to do a proper write-up on it:
https://censys.com/blog/vshell/
Vshell: A Chinese-Language Alternative to Cobalt Strike  - Censys

Vshell is a Go-based remote administration tool that provides post-compromise capabilities for network pivoting and proxying. While the project is marketed as non-malicious, publicly available project materials have referenced offensive tradecraft (e.g., screenshots involving Mimikatz), and the tool has been observed in unauthorized contexts as a means of remote server management.  Its distribution model has […]

Censys