SnappyTCP is a Linux/Unix reverse TCP shell used by the Türkiye-nexus cyberespionage actor Sea Turtle, also tracked as Teal Kurma, Marbled Dust, SILICON, and Cosmic Wolf. Active in campaigns observed from 2021 through 2023, it provides basic command-and-control and interactive shell access and has been used to maintain persistence on compromised hosting and server environments. SnappyTCP conducts an HTTP-based negotiation before spawning a reverse shell. Known variants communicate either in plaintext or through TLS using OpenSSL and certificates. The malware has been executed with nohup to continue operating after an interactive terminal closes. Sea Turtle has used SnappyTCP following access to compromised cPanel environments and SSH services, including in espionage operations targeting organizations in Europe, the Middle East, and North Africa, particularly telecommunications providers, ISPs, IT and media organizations, government-related entities, NGOs, and Kurdish-affiliated targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sea Turtle accessed the target organisation's cPanel Web hosting environment via SSH from a VPN connection, dropped an information-gathering Linux reverse TCP shell called "SnappyTCP" and exfiltrated a copy of the email archive.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Sea Turtle... exfiltrated a copy of the email archive... through a command-and-control (C2) channel using TCP and HTTP.
Sea Turtle... exfiltrated a copy of the email archive... through a command-and-control (C2) channel using TCP and HTTP.
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web shell used by Sea Turtle during intrusion operations to maintain execution and post-compromise access on victim systems.
A Linux/Unix reverse TCP shell/backdoor used by Sea Turtle for persistence and command-and-control. It reads a config file containing a domain and port, performs an HTTP GET request, and if the expected response is returned, spawns a reverse shell to attacker-controlled infrastructure. It was also used to execute commands and facilitate exfiltration of an email archive.
SnappyTCP is a simple reverse TCP shell for Linux/Unix systems, used by the Teal Kurma (Sea Turtle) threat actor for remote command execution, persistence, and command and control. It has at least two variants: one using plaintext communication and another using TLS for secure connections. The malware is used for espionage, enabling the threat actor to collect and exfiltrate sensitive data from targeted organizations.
Malware that uses OpenSSL and TLS certificates to encrypt traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.