Snappybee

Malware updated a year ago (2024-11-29T13:57:54.632Z)
Download STIX
Preview STIX
Snappybee, also known as Deed RAT, is a modular backdoor malware that has been identified as part of the toolkit used by Earth Estries to exploit target machines. It is one of four major tools, including Cobalt Strike and Zingdoor, used by the group to gain control over systems. Snappybee is often deployed through DLL sideloading, similar to Zingdoor, and is considered the successor to ShadowPad, another notorious malware. The malware has been used in sophisticated cyber-attacks against various targets, including government servers in Southeast Asia. The deployment of Snappybee typically occurs in the later stages of the attack routine, often following the installations of other backdoors like Zingdoor and Cobalt Strike, although the order of deployment may vary. This malware is part of two distinct infection chains employed by Earth Estries. In the first chain, tools like PsExec, Trillclient, Hemigate, and Crowdoor are delivered via CAB files. In contrast, the second chain involves the use of malware such as Zingdoor and Snappybee, which are delivered through cURL downloads alongside utility tools like PortScan and NinjaCopy. Earth Estries exploits vulnerable Exchange servers using web shells like ChinaChopper and additional backdoors such as Zingdoor, Snappybee, and Cobalt Strike, showcasing the diversity of their toolkit. Once inside a network, lateral movement is performed by the initial backdoor, with additional backdoors like Zingdoor and Snappybee being installed on other machines within the network. This approach allows for a broad and sustained compromise of the targeted system, enabling data theft, disruption of operations, or ransomware attacks.
Description last updated: 2024-11-28T11:52:40.866Z
What's your take? (Question 1 of 1)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Deed Rat is a possible alias for Snappybee. Deed RAT is a sophisticated malware associated with the Space Pirates group, known for its ability to encapsulate its protocol in HTTP, HTTPS, and DNS. It stores all its data, including configuration and plugins, in the system registry and collects information about in-use proxies through network sn
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Backdoor
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Snappybee Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more