SnappyBee, also known as Deed RAT, is a modular Windows backdoor associated with multiple China-nexus espionage operations and commonly described as a successor to ShadowPad. It has been observed in intrusions attributed to clusters including Salt Typhoon, Earth Estries, FamousSparrow, UAT-8302, and the Space Pirates activity set, indicating either shared tooling or operational overlap across related espionage ecosystems. Victimology linked to SnappyBee activity includes telecommunications providers, government entities, and energy-sector organizations, including an Azerbaijani oil and gas target.
SnappyBee is used for long-term post-compromise access and is typically deployed after initial intrusion rather than as a standalone initial access tool. Documented intrusion chains show it following exploitation of public-facing Microsoft Exchange servers via ProxyNotShell, deployment of web shells, and subsequent execution through DLL sideloading. It has also been deployed in campaigns involving sideloading through legitimate software to blend into victim environments. The malware has been observed alongside other implants such as GhostSpider, ZingDoor, Terndoor, Cobalt Strike, and HemiGate, reflecting its role in broader multi-stage espionage operations.
The malware is modular and supports persistent remote access through plugin-based functionality. Reported tradecraft includes encrypted payload storage, staged in-memory decryption and decompression, runtime API resolution, and evolved DLL sideloading logic designed to delay malicious execution until a legitimate application reaches an expected control-flow path. This execution-gating behavior is consistent with defense evasion and reduced sandbox visibility. SnappyBee has also been associated with registry-based configuration or state tracking and service-based persistence on compromised Windows hosts.
Operational reporting consistently places SnappyBee in sustained espionage campaigns focused on maintaining footholds, supporting lateral movement, and enabling follow-on collection within strategically important networks. Its repeated use by China-linked actors, especially in telecom and government intrusions, makes it a notable backdoor in the contemporary Chinese espionage malware ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The process command line contained the MSExchangePowerShellAppPool argument, indicating that the attacker exploited the Exchange server via the ProxyNotShell exploit chain... ProxyNotShell (CVE-2022-41040, CVE-2022-41082) is a related exploit chain disclosed in 2022. Both allow unauthenticated attackers to execute code on unpatched Exchange servers. | Beyond the delivery mechanism, the operation is characterized by the deployment of two distinct backdoor families, Deed RAT and Terndoor, which were utilized across three separate waves of activity.
The operation deployed two distinct backdoor families, Deed RAT and Terndoor, across different stages.
In their latest campaign, the actor leverages one of the latest WinRAR vulnerabilities that will ultimately lead to running shellcode... Rule names: EE_Loader EE_Dropper WinRAR_ADS_Traversal References / Resources: WinRAR CVE: https://nvd.nist.gov/vuln/detail/CVE-2025-8088
...exploited a public-facing Citrix NetScaler Gateway appliance, likely CVE-2023-3519, for initial access and deployed SnappyBee (also known as Deed RAT)... CVE-2023-3519 is a critical remote code execution (RCE) vulnerability in Citrix Application Delivery Controller (ADC) and Citrix Gateway appliances.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
На серверах (за пределами сетевых устройств) Salt Typhoon разворачивает бэкдор GhostSpider (по данным Trend Micro, разработан специально для телеком-сетей), руткит Demodex (kernel-mode), Cobalt Strike, а также SnappyBee и HemiGate.
Еще один вид ранее неизвестного ВПО, который в единственном экземпляре мы обнаружили у нашего клиента, представляет собой модульный бэкдор.
In one documented intrusion, the group also deployed SNAPPYBEE and ZingDoor together, a tactic independently highlighted by Trend Micro in 2024 reporting on similar China-linked activity.
...used for DLL side-loading in connection with Deed RAT (aka Snappybee) in prior activity attributed to Salt Typhoon...
...used for DLL side-loading in connection with Deed RAT (aka Snappybee) in prior activity attributed to Salt Typhoon...
34 distinct techniques documented for this family, organized by ATT&CK tactic.
Despite remediation attempts, they repeatedly re-entered the network, deploying different backdoors in three distinct waves.
The chain of evidence includes Exchange exploitation (T1190 Exploit Public-Facing Application)... The process command line contained the MSExchangePowerShellAppPool argument, indicating that the attacker exploited the Exchange server via the ProxyNotShell exploit chain.
After opening an interactive remote session, they launched a PowerShell console (T1059.001 PowerShell), and within minutes, LMIGuardianSvc.exe and its associated files appeared on the system.
ShellManager — удаленная командная строка... Приложения MITRE: T1059.003 Command and Scripting Interpreter: Windows Command Shell
ВПО группы Space Pirates использует функции WinAPI для запуска новых процессов и внедрения шеллкода
In their latest campaign, the actor leverages one of the latest WinRAR vulnerabilities that will ultimately lead to running shellcode.
Annotations ID Technique Tactic T1559 Inter-Process Communication Execution
MITRE ATT&CK Mapping... T1569.002 Service Execution LogMeIn Hamachi service executes LMIGuardianSvc.exe at system startup.
"Unlike standard DLL side-loading that relies on simple file replacement, this method overrides two specific exported functions within the malicious library. This creates a two-stage trigger that gates the Deed RAT loader's execution through the host application's natural control flow..."
Deed RAT хранит в реестре все свои данные, включая конфигурацию и плагины
Despite remediation attempts, they repeatedly re-entered the network, deploying different backdoors in three distinct waves.
The recently observed intrusion... followed by web shell deployment, command execution, DLL sideloading, and backdoor deployment.
The third wave brought back a modified Deed RAT using sentinelonepro[.]com as its command-and-control address, impersonating a well-known security vendor to avoid detection in network logs.
При создании сервисов группа Space Pirates использует легитимно выглядящие имена
Группа Space Pirates маскирует свое ВПО под легитимное ПО
The recently observed intrusion... followed by web shell deployment, command execution, DLL sideloading, and backdoor deployment.
MITRE ATT&CK Mapping... T1140 Deobfuscate / Decode Files or Information RC4, AES-CBC, LZNT1, and Deflate decryption/decompression of Deed RAT components and plugins.
The payload only runs after the host application follows a specific internal sequence of calls, meaning a sandbox examining the file in isolation sees no malicious behavior at all.
"Unlike standard DLL side-loading that relies on simple file replacement, this method overrides two specific exported functions within the malicious library. This creates a two-stage trigger that gates the Deed RAT loader's execution through the host application's natural control flow..."
Группа Space Pirates собирает информацию о сетевых параметрах зараженной машины
Группа Space Pirates собирает информацию о пользователях скомпрометированных компьютеров
Deed RAT собирает информацию об используемых прокси с помощью прослушивания трафика
Сразу же после установки соединения с C2 бэкдор собирает и отправляет информацию о системе... Приложения MITRE: T1082
ВПО группы Space Pirates поддерживает работу с несколькими C2 и может обновлять список C2 через веб-страницы
MITRE ATT&CK Mapping... T1071.001 Application Layer Protocol HTTPS C2 to sentinelonepro[.]com:443 and virusblocker[.]it[.]com:443
RS5Manager — использование зараженного компьютера в качестве прокси-сервера... Deed RAT может обнаруживать и использовать прокси для соединения с C2
Группа Space Pirates загружает дополнительные утилиты с управляющего сервера посредством утилиты certutil
ВПО группы Space Pirates может сжимать сетевые сообщения с помощью алгоритмов LZNT1 и LZW
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/backdoor in Salt Typhoon's server-side arsenal mentioned alongside GhostSpider, Demodex, and HemiGate.
Backdoor/RAT used by FamousSparrow in a multi-wave intrusion against an Azerbaijani oil and gas company. It was deployed via DLL sideloading using files disguised as LogMeIn Hamachi, with its payload stored in an encrypted file (.hamachi.lng), decrypted in memory using AES-128 and RC4, and persisted via a Windows service.
A remote access trojan/backdoor deployed by FamousSparrow during multiple waves of intrusion; described as a successor to ShadowPad and used to maintain access to the compromised network.
A backdoor/RAT described as a successor of ShadowPad, deployed in multiple waves during the intrusion to provide persistent access. The campaign used an evolved DLL side-loading technique leveraging the legitimate LogMeIn Hamachi binary to load a rogue DLL that executed the main payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.