SNUGRIDE is a Windows backdoor associated with APT10, also known as MenuPass, and was used during the group’s 2016–2017 resurgence as a first-stage implant. It communicates with command-and-control infrastructure over HTTP and encrypts its command-and-control traffic with AES using a static key. Documented functionality includes system surveying, filesystem access, command execution, and spawning a reverse shell, making it suitable for early foothold establishment and operator-driven post-compromise activity. SNUGRIDE also establishes persistence through a Registry Run key, allowing it to survive reboots and user logons. Reported APT10 operations involving SNUGRIDE targeted organizations across multiple regions and sectors, including manufacturing and IT service providers, as part of broader cyber-espionage activity and downstream access operations via trusted service-provider relationships.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FireEye/Mandiant described HAYMAKER and SNUGRIDE as first-stage backdoors and BUGJUICE and customized QUASARRAT as second-stage backdoors during the 2016–2017 resurgence.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware’s capabilities include taking a system survey, access to the filesystem, executing commands and a reverse shell.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
4H RAT has the capability to create a remote shell. AuditCred can open a reverse shell on the system to execute commands. PlugX allows actors to spawn a reverse shell on a victim. QuasarRAT can launch a remote shell to execute commands on the victim’s machine.
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
First-stage backdoor associated with APT10 activity.
Malware that establishes persistence via a Registry Run key.
Backdoor that encrypts C2 traffic with AES using a static key.
Backdoor malware that persists through a Registry Run key.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.