SnakeDisk is a USB-propagated worm associated with the China-linked espionage cluster Hive0154, also widely tracked as Mustang Panda. It is designed to spread through removable media and appears tailored for operations against isolated, segmented, or otherwise restricted environments where USB devices can bridge network boundaries. Reported activity indicates a strong operational focus on Thailand, with execution gated by public IP geolocation checks that allow the malware to proceed only on systems identified as being in Thailand.
SnakeDisk has been observed as a 32-bit DLL launched through DLL sideloading. It supports multiple execution paths, including one focused on USB infection and propagation and another used to drop and execute follow-on payloads directly. The malware monitors removable-drive activity, detects newly attached USB devices, and infects them by hiding legitimate user files in concealed directories while placing a weaponized executable in the root of the drive under a socially plausible name derived from the device volume. It copies its malicious components and configuration to the removable media and marks selected artifacts as hidden and system files to reduce visibility.
On infected hosts, SnakeDisk can reconstruct and deploy a secondary payload chain that uses a legitimate signed executable to sideload a malicious library. The payload delivered in documented cases is the Yokai backdoor, another Hive0154-linked implant previously associated with Thailand-focused intrusions. Yokai provides remote command execution through a reverse shell and can establish persistence, making SnakeDisk both a propagation mechanism and a delivery vehicle for post-compromise access.
Code and tradecraft overlaps link SnakeDisk to the earlier ToneDisk or WispRider USB worm framework within the broader TONESHELL malware ecosystem. This places SnakeDisk within Mustang Panda’s long-running pattern of combining DLL sideloading, removable-media propagation, and modular backdoor deployment to support espionage operations against government and other strategically relevant targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SnakeDisk: A USB-propagated worm designed to target isolated or segmented environments by deploying a secondary backdoor on selected systems.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
By essentially hiding the files a user expects on their USB, the malware increases the chance of a victim believing the USB has not yet been opened and accidentally clicking the weaponized executable on a new machine bearing the same name as the device.
Next, it creates a new event "Windows External Module" which acts as a mutex to prevent multiple instances from running on the same machine... SnakeDisk then ensures it only runs in a single instance by attempting to open a mutex "Global\\<mutx config value>".
After successfully reading its configuration file, SnakeDisk will try to confirm that it is currently executing on a Thailand-based machine. It sends an HTTP GET request to http://ipinfo[.]io/json and checks if the "country" field matches either "THA" or "TH".
Specifically, it moves the existing files on the USB into a new sub-directory, effectively tricking the victim to click on the malicious payload on a new machine by setting its name to the volume name of the USB device, or "USB.exe." Once the malware is launched, the files are copied back to their original location.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A USB-propagated worm used to reach isolated or segmented environments and deploy a secondary backdoor.
Referenced as part of the malware set in Mustang Panda's tooling evolution.
USB-propagating worm that executes only on devices with Thailand-based IPs and drops the Yokai backdoor (per excerpt).
A previously undocumented USB worm referenced as used alongside an updated ToneShell backdoor in Mustang Panda activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.