Snoopy is a Linux userland backdoor associated with the Cloud Snooper intrusion set. It functions as the companion component to a server-focused Linux kernel rootkit that enables covert command-and-control by manipulating network traffic in ways designed to bypass normal firewall controls. The malware has been linked to long-running activity against internet-facing Linux servers, including victims observed in Asia, and the broader toolset has been assessed as having been in development since at least 2016. Snoopy is notable for its role in post-compromise persistence and remote access on Linux systems, operating alongside a kernel component that provides stealth and network-level evasion. Public reporting has also noted its deployment following exploitation of Ivanti vulnerabilities. The name Snoopy is also used for an unrelated aerial surveillance framework; in malware contexts, it refers to the Cloud Snooper backdoor/rootkit ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We analyzed and described the rootkit’s userland companion backdoor, dubbed ‘Snoopy’, and were able to design detection and scanning methods to identify the rootkit at scale.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Snoopy is malware deployed by attackers exploiting Ivanti Endpoint Manager Mobile vulnerabilities, as detailed in a CISA analysis report.
Userland companion backdoor associated with the Cloud Snooper Linux kernel rootkit, supporting covert command-and-control communications that traverse firewalls.
Snoopy is a digital terrestrial tracking and surveillance framework designed to collect and analyze wireless signals for the purpose of tracking devices and individuals. It is often deployed on aerial platforms such as drones to perform practical aerial hacking and surveillance operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.