Skip to main content
Mallory
MalwareUsed by 2 actors

SNOWYAMBER

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Cloaked Ursa

It’s worth noting that the string encryption algorithms appear to line up with those seen within the Cloaked Ursa SNOWYAMBER and QUARTERRIG malware reports by the Military Counterintelligence Service and CERT.PL.

via palo alto networks unit 42 blogunit42.paloaltonetworks.com
APT29

It’s worth noting that the string encryption algorithms appear to line up with those seen within the Cloaked Ursa SNOWYAMBER and QUARTERRIG malware reports by the Military Counterintelligence Service and CERT.PL.

via palo alto networks unit 42 blogunit42.paloaltonetworks.com
MITRE ATT&CK

Techniques & procedures

13 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1583.006Web ServicesEvidence1

For communication, the payload uses both the Microsoft Graph and Dropbox API... Cloaked Ursa has previously leveraged Dropbox as a C2 server... past reports describing C2 communication via Notion and Google Drive.

Initial Access

1 technique
T1566.001Spearphishing AttachmentEvidence2

Their initial access attempts over the past two years have predominantly used phishing lures with a theme of diplomatic operations... Cloaked Ursa emailed their illegitimate version of this flyer to multiple diplomatic missions throughout Kyiv. These illegitimate flyers use benign Microsoft Word documents of the same name.

Execution

1 technique
T1204.002Malicious FileEvidence1

ISO and IMG disk images, on Windows computers, are automatically mounted in the file system when opened... The actor used various techniques to get the user to launch the malware.

Persistence

1 technique
T1547.009Shortcut ModificationEvidence1

One of them was a Windows shortcut (LNK) file pretending to be a document but actually running a hidden DLL library with the actor's tools.

Privilege Escalation

1 technique
T1547.009Shortcut ModificationEvidence1

One of them was a Windows shortcut (LNK) file pretending to be a document but actually running a hidden DLL library with the actor's tools.

Stealth

2 techniques
T1027Obfuscated Files or InformationEvidence1

The final payload contains a large array of obfuscation techniques, including string encryption and junk functions, as well as modifying exception handling structures... This results in a mangled control flow graph and failed decompilation.

T1140Deobfuscate/Decode Files or InformationEvidence1

Once read into memory, it will decrypt the file using an XOR operation, which results in a secondary shellcode layer.

Discovery

2 techniques
T1033System Owner/User DiscoveryEvidence1

Both tools sent the IP address as well as the computer and user name to the actor. They were used to assess whether the victim was of interest to the actor and whether it was a malware analysis environment.

T1082System Information DiscoveryEvidence1

Both tools sent the IP address as well as the computer and user name to the actor. They were used to assess whether the victim was of interest to the actor and whether it was a malware analysis environment.

Collection

1 technique
T1560.001Archive via UtilityEvidence1

Campaigns observed in the past linked to “NOBELIUM” and “APT29” used .ZIP or .ISO files to deliver the malware. During the campaign described above, .IMG files were also used in addition to the aforementioned file formats.

Command and Control

4 techniques
T1071.001Web ProtocolsEvidence1

For communication, the payload uses both the Microsoft Graph and Dropbox API... If communication fails via the Graph API several times, communication via Dropbox is attempted.

T1102Web ServiceEvidence1

SNOWYAMBER – a tool first used in October 2022, abusing the Notion service to communicate and download further malicious files.

T1105Ingress Tool TransferEvidence2

If the infected workstation passed manual verification, the aforementioned downloaders were used to deliver and start-up the commercial tools COBALT STRIKE or BRUTE RATEL.

T1132Data EncodingEvidence1

Previously, Cloaked Ursa-linked payloads that communicate with Dropbox had wrapped communications in a packet that resembled an MP3 file... In this sample, it appears that they have opted to use BMP files. The threat actor-owned C2 will upload commands to Dropbox that are wrapped in the BMP format.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping13

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.