SnappyTCP is a Linux/Unix reverse TCP shell used for persistence and basic command-and-control. Reporting attributes its use between 2021 and 2023 to the Türkiye-aligned espionage actor Sea Turtle, also tracked as SILICON, Teal Kurma, Marbled Dust, and Cosmic Wolf. It was observed in intrusion operations targeting organizations in Europe, the Middle East, and North Africa, including telecommunications, media, ISPs, IT service providers, government, NGOs, and Kurdish-affiliated targets.
The malware has at least two main variants: a plaintext version and a TLS-secured version. SnappyTCP can use OpenSSL and TLS certificates to encrypt traffic. It performs HTTP-based negotiation before spawning a reverse TCP shell, and reported source-code behavior includes reading a configuration file, issuing an HTTP GET request for sy.php, checking for the header X-Auth-43245-S-20, and then launching the reverse shell if the response matches expected conditions. It has been described as having basic C2 capabilities and as being compiled for multiple architectures and operating systems, including samples with statically linked GLIBC; both executable and shared-object formats were noted.
In observed Sea Turtle operations, SnappyTCP was executed with nohup to keep it running after shell exit, and it was also described as a deployed web shell during intrusion activity. Associated infrastructure mentioned in reporting includes forward.boord[.]info over port 443, as well as domains such as lo0.systemctl.network and ybcd.tech. Reported related IP addresses include 193.34.167[.]245, which also hosted downloadable SnappyTCP source code, and infrastructure analysis also identified 168.100.10.187, 93.115.22.212, and 108.61.103.186. The malware and related tooling reportedly show strong code overlap with a public GitHub repository assessed as likely controlled by the actor.
Observed intrusion context around SnappyTCP included compromise of cPanel accounts, SSH-based access, use of shell scripts to drop executables, local compilation with GCC, installation of Adminer, collection and staging of victim email archives in public web directories, and anti-forensics such as clearing Bash/MySQL history and overwriting Linux logs. Initial access in broader campaigns was reported via exploitation of CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
during one of the most recent campaigns in 2023, a reverse TCP shell named SnappyTCP for Linux/Unix with basic command-and-control capabilities has been used to establishing persistence on systems
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Command and Control T1071.001 T1095 Sea Turtle configured SnappyTCP to establish a command-and-control channel to the domain name forward.boord[.]info on port 443 using the protocols TCP and HTTP.
Command and Control T1071.001 T1095 Sea Turtle configured SnappyTCP to establish a command-and-control channel to the domain name forward.boord[.]info on port 443 using the protocols TCP and HTTP.
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web shell used by Sea Turtle during intrusion operations to maintain execution and post-compromise access on victim systems.
A Linux/Unix reverse TCP shell/backdoor used by Sea Turtle for persistence and command-and-control. It reads a config file containing a domain and port, performs an HTTP GET request, and if the expected response is returned, spawns a reverse shell to attacker-controlled infrastructure. It was also used to execute commands and facilitate exfiltration of an email archive.
SnappyTCP is a simple reverse TCP shell for Linux/Unix systems, used by the Teal Kurma (Sea Turtle) threat actor for remote command execution, persistence, and command and control. It has at least two variants: one using plaintext communication and another using TLS for secure connections. The malware is used for espionage, enabling the threat actor to collect and exfiltrate sensitive data from targeted organizations.
Malware that uses OpenSSL and TLS certificates to encrypt traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.