MysterySnail is a Windows remote access trojan associated with cyber-espionage activity and linked to the IronHusky threat actor. It provides attackers with persistent remote access to compromised systems and has been used in targeted intrusions against organizations in multiple sectors, including campaigns aimed at entities in Russia and Mongolia. MysterySnail has also been observed in operations involving exploitation of Win32k elevation-of-privilege vulnerability CVE-2021-40449, allowing attackers to raise privileges after initial compromise and strengthen control over victim hosts. The malware is characterized as a RAT used for post-compromise access and operator-driven activity on victim machines.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In October 2021, Microsoft patched CVE-2021-40449, another Win32k EoP zero day linked to a remote access trojan known as MysterySnail...
In October 2021, Microsoft patched CVE-2021-40449, another Win32k EoP zero day linked to a remote access trojan known as MysterySnail...
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan (RAT) referenced as being linked to exploitation of a Win32k elevation-of-privilege zero-day (CVE-2021-40449).
Remote Access Trojan (RAT) used in conjunction with CVE-2021-40449 to facilitate privilege escalation and provide attackers remote access to the victim system.
MysterySnail is a remote access trojan (RAT) used for espionage, recently updated by IronHusky to target Russia and Mongolia.
Backdoor identified in side-loading examples via malicious cryptbase.dll variants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.