mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
36 lines
2.1 KiB
YAML
36 lines
2.1 KiB
YAML
name: Snake Malware
|
|
id: 032bacbb-f90d-43aa-bbcc-d87f169a29c8
|
|
version: 1
|
|
date: '2023-05-10'
|
|
author: Michael Haag, Splunk
|
|
status: production
|
|
description: The Snake implant is considered the most sophisticated cyber espionage tool designed and used by Center 16 of Russia's Federal Security Service (FSB) for long-term intelligence collection on sensitive targets.
|
|
narrative: The Snake implant is considered the most sophisticated cyber espionage tool designed and used by
|
|
Center 16 of Russia's Federal Security Service (FSB) for long-term intelligence collection on sensitive
|
|
targets. To conduct operations using this tool, the FSB created a covert peer-to-peer (P2P) network of
|
|
numerous Snake-infected computers worldwide. Many systems in this P2P network serve as relay
|
|
nodes which route disguised operational traffic to and from Snake implants on the FSB's ultimate
|
|
targets. Snake's custom communications protocols employ encryption and fragmentation for
|
|
confidentiality and are designed to hamper detection and collection efforts.
|
|
We consider Snake to be the most sophisticated cyber espionage tool in the FSB's arsenal. The
|
|
sophistication of Snake stems from three principal areas. First, Snake employs means to achieve a
|
|
rare level of stealth in its host components and network communications. Second, Snake's internal
|
|
technical architecture allows for easy incorporation of new or replacement components. This design
|
|
also facilitates the development and interoperability of Snake instances running on different host
|
|
operating systems. We have observed interoperable Snake implants for Windows, MacOS, and Linux
|
|
operating systems. Lastly, Snake demonstrates careful software engineering design and
|
|
implementation, with the implant containing surprisingly few bugs given its complexity. (CISA, 2023)
|
|
references:
|
|
- https://media.defense.gov/2023/May/09/2003218554/-1/-1/0/JOINT_CSA_HUNTING_RU_INTEL_SNAKE_MALWARE_20230509.PDF
|
|
tags:
|
|
category:
|
|
- Adversary Tactics
|
|
- Account Compromise
|
|
- Lateral Movement
|
|
- Privilege Escalation
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Advanced Threat Detection
|