TF-MAL-elf.snappy_tcp
📛 Threat Title
Malware family: SnappyTCP
Description
ThreatFox malware family `elf.snappy_tcp`. Printable name: SnappyTCP.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
The threat actor uses SnappyTCP alongside the tool NoHup to establish persistence on systems, ensuring the malware continues to run even after exiting the shell or terminal. The attacker further installs Adminer, a publicly available database management tool, indicating an intent to remotely access MySQL services.
-
web:attack.mitre.org
SnappyTCP is a web shell used by Sea Turtle between 2021 and 2023 against multiple victims. SnappyTCP appears to be based on a public GitHub project that has since been removed from the code-sharing site.
-
web:cybernoz.com
Execute commands Exfiltrate data Compromise the system's security Cybersecurity researchers at PwC recently discovered a reverse TCP shell for Linux or Unix systems with C2 capabilities while analyzing one of the malware of Teal Kurma (a.k.a. Sea Turtle, Marbled Dust, Cosmic Wolf) dubbed 'SnappyTCP' .
-
web:cybersecuritynews.com
Recent infrastructure in 2023 linked to SnappyTCP via CERT alert indicators. Malware scans for "X-Auth-43245-S-20" and "\r\n\r\n" in HTTP request, then triggers TCP reverse shell. Using OpenSSL and TLS certificates for a secure link, the malware , in other cases, connects to an IP from the conf file, and then it sends:-
-
web:hivepro.com
Sea Turtle, a Turkey-based Advanced Persistent Threat (APT) actor, has been active since 2017. The group has primarily targeted European and Middle Eastern organizations, focusing on information theft and DNS hijacking to compromise repositories with valuable and sensitive data. In a recent 2023 campaign, targeting the Netherlands, Sea Turtle utilized a reverse TCP shell named SnappyTCP for ...
-
web:malpedia.caad.fkie.fraunhofer.de
According to PwC, SnappyTCP is a simple reverse shell for Linux/Unix systems, with variants for plaintext and TLS communication. SeaTurtle has used SnappyTCP at least between 2021 and 2023.
-
web:misp-galaxy.org
SnappyTCP is a web shell used by Sea Turtle between 2021 and 2023 against multiple victims. SnappyTCP appears to be based on a public GitHub project that has since been removed from the code-sharing site.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.infosecurity-magazine.com
cPanel Compromise and SnappyTCP Malware Previously known to carry out DNS hijacking, Sea Turtle has deployed new approaches in recent campaigns. During one of the 2023 operations the group reportedly used a compromised account on cPanel, a web hosting control panel used by multiple organizations worldwide, from an IP address used by a VPN provider.
-
web:www.pwc.com
The threat actor has since continued to target similar sectors but has altered its capabilities in a likely attempt to evade detection. In this blog, we will detail Linux/Unix malware samples previously not discussed publicly that PwC has named " SnappyTCP ". The following are the key points of our analysis:
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.