SNEEPY, also known as ByeByeShell, is a Windows backdoor associated with targeted intrusion activity reported since 2013 and linked through overlapping infrastructure to the malware cluster commonly tracked as CONFUCIUS_A. It has been used primarily against targets in Pakistan, the Middle East, and other parts of Asia, with occasional enterprise victims observed elsewhere. Campaigns attributed to this activity have been assessed as likely tied to operators of probable Indian origin.
SNEEPY-related operations commonly relied on email-delivered executable lures rather than conventional document attachments alone. Observed themes included event invitations, political and news content, pornographic bait, and fake software updates. In some cases, operators also used self-extracting binaries and exploit-builder-generated delivery artifacts.
A notable characteristic of later SNEEPY-linked tooling is covert command-and-control discovery through legitimate web services rather than direct DNS resolution. Samples associated with the CONFUCIUS_A lineage retrieved content from public websites such as Quora and extracted encoded values from specific text regions, then decoded those values through a large word-to-byte lookup table to derive command-and-control addresses. This technique allowed early-stage network traffic to blend with benign browsing activity to well-known services.
The malware’s role is consistent with a backdoor used for persistent remote access and post-compromise control. High-confidence reporting links SNEEPY to overlapping command-and-control infrastructure with CONFUCIUS_A samples, suggesting either lineage continuity or shared development. The broader activity cluster indicates a long-running espionage-oriented capability focused on regional geopolitical targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
In most cases where we have been able to identify the droppers, the attack begins with an executable file being sent directly to targets via e-mail. Occasionally the attackers leverage builders for known document exploits, but most of the time they still use self-extracting binaries. The themes of the phishing e-mails vary according to the target...
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named shell malware referenced in the summary table as associated with one of the linked threat clusters.
Backdoor malware/method associated with earlier attacks that share command-and-control infrastructure and delivery similarities with CONFUCIUS_A.
Backdoor attack method/family linked in the article to attacks associated with CONFUCIUS_A; shared command-and-control addresses across multiple samples are cited as the connection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.