Cloud Snooper is a threat actor associated with Linux-focused intrusions against server and cloud-oriented environments. The group is known for a server-oriented Linux kernel rootkit that hooks netfilter traffic-control functions to create covert command-and-control channels capable of traversing firewalls, paired with a userland backdoor referred to as Snoopy. Reporting indicates the toolset may have been in development since at least 2016 and has been observed targeting servers in Asia. Cloud Snooper has also been associated with use of NoodleRAT in cloud-focused operations. The actor is assessed as linked to Chinese-speaking operators and is generally characterized as a suspected nation-state or state-aligned espionage cluster rather than a financially motivated intrusion set. Its tradecraft emphasizes stealthy post-compromise access on Linux systems, covert communications, persistence, and data access within server infrastructure, making it notable for targeting Linux workloads that can provide strategic access to sensitive enterprise and cloud environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cloud Snooper is a suspected nation-state threat actor associated with the use of NoodleRAT malware in attacks against cloud environments, particularly in the Asia-Pacific region.
Uses a Linux kernel rootkit and companion backdoor for covert command-and-control on servers, including targeted servers in Asia.
Cloud Snooper is a Linux malware family used to bypass firewalls and target cloud environments.
Mentioned as a newer active actor in Southeast Asia; no additional operational detail provided in this text.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.