Deed RAT, also known as SnappyBee, is a modular Windows remote-access Trojan in the ShadowPad malware lineage. It is regarded as an evolution or successor of ShadowPad and uses a custom loader and encrypted, compressed payload and plugin architecture. Observed variants support command-and-control communications, host-information collection, component updates and removal, proxy management, persistence, anti-debugging and anti-sandbox checks, process creation, and code injection. Some variants use named-pipe functionality and store configuration data containing operational settings, process-injection targets, and command-and-control information.
Deed RAT has been deployed through DLL sideloading, including chains that abuse legitimate signed applications and delay execution until expected host-program control flow occurs, complicating automated analysis. It has also been observed following exploitation of Microsoft Exchange servers and web-shell deployment, with service-based persistence used in some intrusions.
The malware has been associated with China-nexus espionage activity and is considered a shared tool within that ecosystem. It has been linked to Space Pirates and observed in operations attributed to Earth Estries, FamousSparrow, Salt Typhoon, and UAT-8302. Documented targeting includes government, telecommunications, and energy-sector organizations across multiple regions, including South Caucasus energy infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
We have observed them exploiting server-based N-day vulnerabilities, including the following: CVE-2023-48788 Fortinet FortiClient EMS SQL Injection Vulnerability
CVE-2022-3236 A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.
We have observed them exploiting server-based N-day vulnerabilities, including the following: Ivanti Connect Secure VPN Exploitation (CVE-2023-46805 and CVE-2024-21887) A chain of exploits to bypass authentication, craft malicious requests, and execute arbitrary commands with elevated privileges.
We have observed them exploiting server-based N-day vulnerabilities, including the following: Ivanti Connect Secure VPN Exploitation (CVE-2023-46805 and CVE-2024-21887) A chain of exploits to bypass authentication, craft malicious requests, and execute arbitrary commands with elevated privileges.
The process command line contained the MSExchangePowerShellAppPool argument, indicating that the attacker exploited the Exchange server via the ProxyNotShell exploit chain... ProxyNotShell (CVE-2022-41040, CVE-2022-41082) is a related exploit chain disclosed in 2022. Both allow unauthenticated attackers to execute code on unpatched Exchange servers. | Beyond the delivery mechanism, the operation is characterized by the deployment of two distinct backdoor families, Deed RAT and Terndoor, which were utilized across three separate waves of activity.
The operation deployed two distinct backdoor families, Deed RAT and Terndoor, across different stages.
In their latest campaign, the actor leverages one of the latest WinRAR vulnerabilities that will ultimately lead to running shellcode... Rule names: EE_Loader EE_Dropper WinRAR_ADS_Traversal References / Resources: WinRAR CVE: https://nvd.nist.gov/vuln/detail/CVE-2025-8088
...exploited a public-facing Citrix NetScaler Gateway appliance, likely CVE-2023-3519, for initial access and deployed SnappyBee (also known as Deed RAT)... CVE-2023-3519 is a critical remote code execution (RCE) vulnerability in Citrix Application Delivery Controller (ADC) and Citrix Gateway appliances.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Deed RAT was FamousSparrow's primary backdoor... BloodAlchemy... sits in the ShadowPad and Deed RAT malware lineage.
しかし、私たちは調査の結果、BloodAlchemy は完全に新種のマルウェアではなく、ShadowPad の後継である DeedRAT のさらなる進化版であることを発見しました。
In one documented intrusion, the group also deployed SNAPPYBEE and ZingDoor together, a tactic independently highlighted by Trend Micro in 2024 reporting on similar China-linked activity.
...used for DLL side-loading in connection with Deed RAT (aka Snappybee) in prior activity attributed to Salt Typhoon...
...used for DLL side-loading in connection with Deed RAT (aka Snappybee) in prior activity attributed to Salt Typhoon...
35 distinct techniques documented for this family, organized by ATT&CK tactic.
After opening an interactive remote session, they launched a PowerShell console (T1059.001 PowerShell), and within minutes, LMIGuardianSvc.exe and its associated files appeared on the system.
ShellManager — удаленная командная строка... Приложения MITRE: T1059.003 Command and Scripting Interpreter: Windows Command Shell
ВПО группы Space Pirates использует функции WinAPI для запуска новых процессов и внедрения шеллкода
In their latest campaign, the actor leverages one of the latest WinRAR vulnerabilities that will ultimately lead to running shellcode.
Deed RAT хранит в реестре все свои данные, включая конфигурацию и плагины
Despite remediation attempts, they repeatedly re-entered the network, deploying different backdoors in three distinct waves.
The recently observed intrusion... followed by web shell deployment, command execution, DLL sideloading, and backdoor deployment.
The third wave brought back a modified Deed RAT using sentinelonepro[.]com as its command-and-control address, impersonating a well-known security vendor to avoid detection in network logs.
При создании сервисов группа Space Pirates использует легитимно выглядящие имена
Группа Space Pirates маскирует свое ВПО под легитимное ПО
The recently observed intrusion... followed by web shell deployment, command execution, DLL sideloading, and backdoor deployment.
MITRE ATT&CK Mapping... T1140 Deobfuscate / Decode Files or Information RC4, AES-CBC, LZNT1, and Deflate decryption/decompression of Deed RAT components and plugins.
Группа Space Pirates собирает информацию о сетевых параметрах зараженной машины
Группа Space Pirates собирает информацию о пользователях скомпрометированных компьютеров
Deed RAT собирает информацию об используемых прокси с помощью прослушивания трафика
Сразу же после установки соединения с C2 бэкдор собирает и отправляет информацию о системе... Приложения MITRE: T1082
ВПО группы Space Pirates поддерживает работу с несколькими C2 и может обновлять список C2 через веб-страницы
MITRE ATT&CK Mapping... T1071.001 Application Layer Protocol HTTPS C2 to sentinelonepro[.]com:443 and virusblocker[.]it[.]com:443
RS5Manager — использование зараженного компьютера в качестве прокси-сервера... Deed RAT может обнаруживать и использовать прокси для соединения с C2
we found that the attackers downloaded malicious tools from their C&C server (23.81.41[.]166)
ВПО группы Space Pirates может сжимать сетевые сообщения с помощью алгоритмов LZNT1 и LZW
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-nexus remote-access backdoor in the lineage associated with BloodAlchemy. The content identifies it as FamousSparrow's primary backdoor in a separate Azerbaijani energy-targeting campaign.
A modular backdoor shared among Chinese APT groups and used by Earth Estries after initial compromise for long-term espionage and follow-on operations.
Named malware/backdoor in Salt Typhoon's server-side arsenal mentioned alongside GhostSpider, Demodex, and HemiGate.
Backdoor/RAT used by FamousSparrow in a multi-wave intrusion against an Azerbaijani oil and gas company. It was deployed via DLL sideloading using files disguised as LogMeIn Hamachi, with its payload stored in an encrypted file (.hamachi.lng), decrypted in memory using AES-128 and RC4, and persisted via a Windows service.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.