# Snake

> As of 2026-07-06, Snake is a threat actor tracked by Threadlinqs Intelligence across 4 threats spanning malware, apt. ATT&CK coverage spans 67 techniques across 14 tactics in 4 of 4 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1036 (Masquerading), T1041 (Exfiltration Over C2 Channel).

- **Tracked threats:** 4
- **Categories:** MALWARE, APT
- **As of:** 2026-07-06

## ATT&CK techniques observed

67 techniques observed across 4 of 4 tracked threats. Tactics: Discovery (11), Stealth (formerly Defense Evasion) (10), Command and Control (9), Resource Development (7), Collection (5), Execution (5).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 4 of 4 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 4 of 4 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 4 of 4 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 4 of 4 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 4 of 4 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 4 of 4 tracked threats
- [T1497](https://intel.threadlinqs.com/technique/T1497) Virtualization/Sandbox Evasion — Stealth (formerly Defense Evasion) — observed in 4 of 4 tracked threats
- [T1547](https://intel.threadlinqs.com/technique/T1547) Boot or Logon Autostart Execution — Persistence — observed in 4 of 4 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 4 of 4 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 3 of 4 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 3 of 4 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 4 tracked threats
- [T1033](https://intel.threadlinqs.com/technique/T1033) System Owner/User Discovery — Discovery — observed in 3 of 4 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 3 of 4 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 3 of 4 tracked threats

## Tracked threats

- [Amadey: Commodity Loader/Botnet Evolved into RAT — Dominant LockBit 3.0 Loader, Adopted by FSB's Secret Blizzard Against Ukrainian Military](https://intel.threadlinqs.com/threat/TL-2026-1029) — HIGH
- [Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088](https://intel.threadlinqs.com/threat/TL-2026-0966) — HIGH
- [Kazuar P2P Botnet Evolution — Secret Blizzard (Russia FSB Center 16) Modular Espionage Implant with Kernel/Bridge/Worker Architecture](https://intel.threadlinqs.com/threat/TL-2026-0519) — HIGH
- [Turla Kazuar V3: Satellite DLL SideLoading via MFC Binaries — FSB-Attributed .NET Modular Implant with HP Printer Impersonation](https://intel.threadlinqs.com/threat/TL-2026-0084) — MEDIUM

## Related CVEs

1 CVE referenced by tracked Snake activity.

- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Snake
