Activity timeline
Snake appears in 4 tracked threats between and ; the busiest month was 2026-02 with 1 report.
ATT&CK techniques observed
- T1005 Data from Local System — Collectionobserved in 4 of 4 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 4 of 4 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 4 of 4 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 4 of 4 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 4 of 4 tracked threats
- T1497 Virtualization/Sandbox Evasion — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
- T1547 Boot or Logon Autostart Execution — Persistenceobserved in 4 of 4 tracked threats
- T1566 Phishing — Initial Accessobserved in 4 of 4 tracked threats
- T1016 System Network Configuration Discovery — Discoveryobserved in 3 of 4 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 3 of 4 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
- T1033 System Owner/User Discovery — Discoveryobserved in 3 of 4 tracked threats
- T1057 Process Discovery — Discoveryobserved in 3 of 4 tracked threats
- T1083 File and Directory Discovery — Discoveryobserved in 3 of 4 tracked threats
Tracked threats
- Amadey: Commodity Loader/Botnet Evolved into RAT — Dominant LockBit 3.0 Loader, Adopted by FSB's Secret Blizzard Against Ukrainian MilitaryHIGH
- Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088HIGH
- Kazuar P2P Botnet Evolution — Secret Blizzard (Russia FSB Center 16) Modular Espionage Implant with Kernel/Bridge/Worker ArchitectureHIGH
- Turla Kazuar V3: Satellite DLL SideLoading via MFC Binaries — FSB-Attributed .NET Modular Implant with HP Printer ImpersonationMEDIUM