Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-02

Snake

As of 2026-07-06, Snake is a threat actor tracked by Threadlinqs Intelligence across 4 threats spanning malware, apt. ATT&CK coverage spans 67 techniques across 14 tactics in 4 of 4 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1036 (Masquerading), T1041 (Exfiltration Over C2 Channel).

Tracked threats
43 high · 1 medium
First seen
2026-02-13
Last seen
2026-07-01
ATT&CK techniques
67across 4 of 4 threats
Related CVEs
1Referenced by its activity
4 tracked threat(s) · Categories: MALWARE, APT

Activity timeline

Snake appears in 4 tracked threats between and ; the busiest month was 2026-02 with 1 report.

ATT&CK techniques observed

67 techniques observed across 4 of 4 tracked threats · Discovery (11), Stealth (formerly Defense Evasion) (10), Command and Control (9), Resource Development (7), Collection (5), Execution (5)
  • T1005 Data from Local System — Collectionobserved in 4 of 4 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 4 of 4 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 4 of 4 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 4 of 4 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 4 of 4 tracked threats
  • T1497 Virtualization/Sandbox Evasion — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
  • T1547 Boot or Logon Autostart Execution — Persistenceobserved in 4 of 4 tracked threats
  • T1566 Phishing — Initial Accessobserved in 4 of 4 tracked threats
  • T1016 System Network Configuration Discovery — Discoveryobserved in 3 of 4 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 3 of 4 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
  • T1033 System Owner/User Discovery — Discoveryobserved in 3 of 4 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 3 of 4 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 3 of 4 tracked threats

Tracked threats

Related CVEs

1 CVE referenced by tracked Snake activity