Uroburos, also known as Snake, is a sophisticated modular Windows rootkit and cyber-espionage implant associated with the Russian state-linked Turla group. It comprises a kernel driver and encrypted virtual file system, enabling covert execution of commands, concealment of malicious activity, collection and theft of files, and network-traffic capture. Its peer-to-peer architecture permits compromised hosts to relay commands and collected data through other infected systems, including across segmented networks and through hosts with Internet connectivity. Uroburos has targeted high-value organizations, including government institutions, research organizations, large enterprises, intelligence-related entities, and news organizations. It supports 32-bit and 64-bit Windows environments and has been linked technically and operationally to Turla activity involving Agent.BTZ/ComRAT. Turla has also abused a vulnerable third-party driver in conjunction with Uroburos to disable Windows kernel security protections.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The first type of downloader we’ve seen used to deploy Snake are RTF documents containing the well-known Microsoft Office Equation Editor exploit (CVE-2017-11882). | Snake is a modular .NET keylogger and credential stealer first spotted in late November 2020.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Snake is an implant developed and used by the Russian state-affiliated APT group Turla (aka. Venomous Bear, Waterbug). Snake is used to establish long-term persistence on victim devices and stealthily exfiltrate sensitive data.
Les victimes étaient des entités ministérielles, visées par exemple en 2014 par le code malveillant Uroburos.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Malicious actors distribute Snake as attachments to phishing emails with various themes, such as payment requests. The attachments are typically archive files with file name extensions such as img, zip, tar, and rar, and store a .NET executable that implements the Snake malware.
First, SNAKE uses WMI queries to refer the domain role value.
CF_Secretaria creates a scheduled task named, for example, Updates\vxhnIvyvbHAK. To create this scheduled task, CF_Secretaria issues the following command: C:\Windows\System32\schtasks.exe /Create /TN Updates\vxhnIvyvbHAK /XML C:\Users\User\AppData\Local\Temp\tmp55AB.tmp
CF_Secretaria creates a scheduled task named, for example, Updates\vxhnIvyvbHAK. To create this scheduled task, CF_Secretaria issues the following command: C:\Windows\System32\schtasks.exe /Create /TN Updates\vxhnIvyvbHAK /XML C:\Users\User\AppData\Local\Temp\tmp55AB.tmp
CF_Secretaria creates a scheduled task named, for example, Updates\vxhnIvyvbHAK. To create this scheduled task, CF_Secretaria issues the following command: C:\Windows\System32\schtasks.exe /Create /TN Updates\vxhnIvyvbHAK /XML C:\Users\User\AppData\Local\Temp\tmp55AB.tmp
It confirmed that the government institution had been infected with the spyware Uroburos, which is also called "Snake" in some cases.
一般的なランサムウェアは一ファイルずつファイルを暗号化→拡張子変更の流れをとるのではなく、全てのファイルに対する暗号化を一通り実施した後に、最後にまとめてファイルの拡張子だけを変更していきます。...挙動検知などに対する検知逃れの効果などが考えられます。
The Snake malware uses the SetWindowsHookExA and CallNextHookEx functions to capture key press events.
Snake first invokes the netsh wlan show profile command to list existing wireless network profiles and then retrieves these from the command output.
A unique feature of this specimen is that it specially works when the work environment is a domain controller... First, SNAKE uses WMI queries to refer the domain role value.
Snake can gather the following type of information about the compromised environment in which the malware runs: Operating system and hardware information: Snake obtains the operating system name and version, amount of hard disk and physical memory, and machine name.
The Snake malware gathers operating system, hardware, geolocation, and date-time information.
Snake can steal saved credentials from credential databases of communication platforms, FTP clients, email clients, and web browsers.
The Snake malware uses the SetWindowsHookExA and CallNextHookEx functions to capture key press events.
We extracted the configuration from each sample in order to obtain the c2 address... more than seventy previously unknown live IP & DNS addresses indicating the ongoing abuse of satellite internet providers operating in both Africa & the Middle East.
Snake can exfiltrate logged keystrokes and stolen credentials, clipboard data, and screenshots using the following protocols: FTP... SMTP... Telegram/HTTPS... Snake can exfiltrate logged keystrokes, screenshots, clipboard data, and credentials on a regularly timed interval.
Snake can exfiltrate logged keystrokes, screenshots, clipboard data, and credentials on a regularly timed interval.
netsh advfirewall set allprofiles firewallpolicy blockinbound,blockoutbound / netsh advfirewall set allprofiles state on
71 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
101 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A keylogger and information stealer.
Russian malware used against Ukrainian government systems in the context of pre-invasion cyber espionage and disruption.
A sophisticated long-term cyberespionage implant used for covert access, persistence, and strategic intelligence collection.
Ransomware family mentioned as targeting healthcare and medical facilities during the COVID period.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.