SnakeDisk is a Windows USB-propagating worm attributed to the China-aligned Hive0154/Mustang Panda ecosystem. First observed in 2025, it is a 32-bit DLL typically launched through DLL side-loading. SnakeDisk is geofenced to execute only when the victim’s public IP address is geolocated to Thailand, indicating a focused operational interest in Thai targets. It monitors for newly connected removable storage, infects removable drives, conceals existing user files in hidden directories, and leaves a malicious executable styled after the drive volume to induce execution. It copies malicious components and configuration data to infected media, enabling propagation into segmented or potentially air-gapped Windows environments. SnakeDisk deploys the Yokai backdoor as a secondary payload; Yokai provides remote command execution through a reverse shell and can establish scheduled-task persistence. SnakeDisk shares code and tradecraft overlaps with the related ToneDisk/WispRider USB worm framework and is associated with other Hive0154 tooling, including TONESHELL and PUBLOAD.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
By essentially hiding the files a user expects on their USB, the malware increases the chance of a victim believing the USB has not yet been opened and accidentally clicking the weaponized executable on a new machine bearing the same name as the device.
Next, it creates a new event "Windows External Module" which acts as a mutex to prevent multiple instances from running on the same machine... SnakeDisk then ensures it only runs in a single instance by attempting to open a mutex "Global\\<mutx config value>".
After successfully reading its configuration file, SnakeDisk will try to confirm that it is currently executing on a Thailand-based machine. It sends an HTTP GET request to http://ipinfo[.]io/json and checks if the "country" field matches either "THA" or "TH".
Specifically, it moves the existing files on the USB into a new sub-directory, effectively tricking the victim to click on the malicious payload on a new machine by setting its name to the volume name of the USB device, or "USB.exe." Once the malware is launched, the files are copied back to their original location.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned solely as a comparison to prior USB-borne tradecraft; the content provides no functional details about it.
Mentioned only as a comparison to prior USB-borne tradecraft; no operational details are provided in this reference.
A USB-propagated worm used to reach isolated or segmented environments and deploy a secondary backdoor.
Referenced as part of the malware set in Mustang Panda's tooling evolution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.