Snake, also known as Uroburos, is a highly sophisticated Windows cyberespionage implant and rootkit associated with the Russian state-linked Turla intrusion set, which has been publicly attributed to FSB Center 16. It has been a core component of long-running espionage operations for well over a decade and has been used against high-value government, diplomatic, defense, justice, and technology targets, including ministries and other sensitive state institutions.
The malware is notable for stealth, persistence, and long-term covert access. It uses kernel-mode components and a hidden virtual filesystem, stores configuration material in the Windows Registry, and can register itself as a service to maintain persistence and load additional components such as its kernel driver and loader. Snake/Uroburos also queries the Registry to locate and decrypt internal components, reflecting a modular architecture designed to conceal functionality and complicate forensic analysis.
For command and control, Snake/Uroburos uses encrypted communications and can tunnel larger data exchanges over a custom HTTP-based protocol that blends with ordinary web traffic. Reported implementations include layered cryptography using mechanisms such as Diffie-Hellman key exchange combined with a pre-shared key for protecting higher-level communications. Embedded queueing and staging functionality supports storage of executable components, key material, communication channels, and operational parameters.
Snake/Uroburos is widely regarded as one of the most advanced espionage implants linked to Russian intelligence. It has been deployed as part of Turla’s broader tradecraft, which has included spearphishing, watering-hole activity, exploitation of internet-facing systems, and abuse of compromised infrastructure to support covert intelligence collection and sustained access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Snake, described by CISA and allied agencies as the most sophisticated cyberespionage implant attributed to FSB Center 16, remained active against selected targets for years.
Les victimes étaient des entités ministérielles, visées par exemple en 2014 par le code malveillant Uroburos.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The very long and deep execution chain and injection of design from user mode to kernel mode is top elite level... finally it uses PsSetCreateProcessNotifyRoutine to register NotifyRoutine for kernel callbacks; from there, the key point is to inject the whole design and hijack the new process created.
This static analysis reveals that Turla’s Uroboros rootkit employs kernel-level privilege escalation...
From the HTTP request parsing with a specific “type” (==6) and the code comparison with the strings “&a” and the XOR description routine, it is a typical XOR loop, using a static decryption table (unk_65D70). The input (e.g., from &a=) is probably encrypted, and this routine decrypts it.
Description Generated datasets for Windows Possible Turla Snake Malware Installer in attack range. MITRE ATT&CK Techniques Environment Details Datasets The following datasets were collected during this attack simulation: Snapattack Path: /datasets/attack_techniques/T1027.009/snapattack/snaattack.log
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
The very long and deep execution chain and injection of design from user mode to kernel mode is top elite level... finally it uses PsSetCreateProcessNotifyRoutine to register NotifyRoutine for kernel callbacks; from there, the key point is to inject the whole design and hijack the new process created.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
ndis.sys handles network traffic, and fwpkclnt.sys is part of the Windows Firewall; patching them is ideal for stealthy network filtering and intercepting packets.
The malware Uroboros uses ZwQuerySystemInformation to enumerate processes, find services such as service.exe, svchost.exe, and browsers (iexplore/firefox/chrome), and determine which is the best place to inject or hide by privilege.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
"By infiltrating Turla's network of hacked machines and sending the malware a command to delete itself"
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2. APT28 has routed traffic over Tor and VPN servers to obfuscate their activities. A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
66 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated long-term cyberespionage implant used for covert access, persistence, and strategic intelligence collection.
Custom malware family associated with Turla and used in its espionage operations.
Malware used in espionage operations attributed here to the Turla/FSB activity; it was used to target French ministerial entities in 2014.
Snake is described as a malware strain used in Russian-backed espionage campaigns for nearly two decades.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.