MarsSnakeLoader is a malware loader used by the China-aligned threat activity cluster UnsolicitedBooker to deploy the MarsSnake backdoor. It has been observed in phishing-led intrusion chains targeting telecommunications organizations in Kyrgyzstan and Tajikistan, with related activity linked to earlier targeting in Saudi Arabia. Delivery commonly begins with phishing emails containing malicious Microsoft Office documents; when opened, the documents prompt users to enable content, triggering macros that install MarsSnakeLoader, which then deploys MarsSnake. Reporting also notes a late November 2025 campaign using MarsSnakeLoader for MarsSnake delivery. The resulting MarsSnake backdoor is described as capable of system reconnaissance, harvesting system metadata, arbitrary command execution, reading and writing files on disk, and data exfiltration. The broader activity has shown tactical overlaps with Space Pirates, use of rare Chinese-origin tools, and in at least one case use of a compromised router as command-and-control infrastructure. No standalone indicators of compromise specific to MarsSnakeLoader are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
When opened, these documents trigger macros that deploy malware loaders like LuciLoad or MarsSnakeLoader, which then deliver the respective backdoors.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware loader delivered via malicious Office macros; used to deliver the MarsSnake backdoor.
Loader used to deploy the MarsSnake backdoor in phishing-driven intrusion chains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.