MarsSnake is a backdoor used by the China-aligned threat activity cluster UnsolicitedBooker (active since at least March 2023). It has been reported in campaigns targeting telecommunications companies in Kyrgyzstan and Tajikistan, representing a shift from earlier targeting of Saudi Arabian entities; it was also reported by ESET in connection with an attack on an unnamed international organization in Saudi Arabia. Positive Technologies reported signs that MarsSnake was also used in attacks targeting China.
Delivery and execution observed in the reporting includes phishing emails leading to malicious Microsoft Office documents that prompt victims to enable macros; the macros deploy a loader (MarsSnakeLoader) which then installs MarsSnake. In at least one case, MarsSnake was launched without a loader via a Windows shortcut masquerading as a Word document (*.doc.lnk), where the LNK executed a batch script that launched a Visual Basic Script, which then launched MarsSnake. The LNK-based chain was assessed to be based on the publicly available FTPlnk_phishing tool (based on identical LNK creation time and Machine ID indicators), and similar LNK tradecraft was noted as used by Mustang Panda in 2022 attacks targeting Thailand.
Capabilities attributed to MarsSnake in the content include system reconnaissance/harvesting system metadata, arbitrary command execution, and file operations (read/write) with data exfiltration. The broader UnsolicitedBooker activity around these intrusions included use of rare Chinese-origin tools, tactical overlaps with the Space Pirates cluster, and command-and-control infrastructure that in some cases used compromised routers as C2 servers and in some attacks mimicked Russian infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used in targeted intrusions; capable of collecting system information, executing arbitrary commands, and exfiltrating data.
Backdoor used to harvest system metadata, execute arbitrary commands, and read/write files on disk; deployed via phishing chains and also observed launched via LNK→BAT→VBS without a loader in at least one case.
Backdoor used in a campaign targeting telecommunications companies in Kyrgyzstan and Tajikistan.
Previously undocumented backdoor used in a multi-year intrusion against a Saudi-based organization by a China-aligned threat actor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.