Deed RAT, also known as SnappyBee, is a modular Windows remote-access trojan and backdoor in the ShadowPad malware lineage. It is shared among multiple China-nexus espionage groups, with documented use by Space Pirates, Earth Estries, FamousSparrow, and UAT-8302. It supports long-term access to compromised organizations, remote shell execution through a dynamically downloaded plugin, and modular expansion of its functionality. Its command-and-control infrastructure has also been associated with exfiltrated victim documents.
Deed RAT is deployed through DLL sideloading using legitimate signed applications, including Trend Micro software and LogMeIn Hamachi. Its loading chains decrypt and decompress payloads before executing them in memory. The malware uses custom module formats, encrypted configuration data, and registry-stored plugins, and establishes persistence through Windows services or registry mechanisms. Its communications support TCP, TLS, HTTP, HTTPS, UDP, and DNS, with additional support for DNS-over-HTTPS resolution, proxy discovery, scheduled connection restrictions, and web-based command-and-control updates.
Updated variants observed in 2025–2026 changed module headers and plugin compression routines. A LogMeIn Hamachi-based loading chain split malicious execution across DLL exports and patched a Windows service-dispatch API, delaying payload execution until the legitimate application followed its normal control flow to impede automated analysis. Deed RAT was deployed after Microsoft Exchange ProxyNotShell exploitation in a sustained intrusion against an Azerbaijani oil and gas company. Other deployments have occurred in government and telecommunications espionage operations, including activity in Asia, South America, and southeastern Europe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
We have observed them exploiting server-based N-day vulnerabilities, including the following: CVE-2023-48788 Fortinet FortiClient EMS SQL Injection Vulnerability
CVE-2022-3236 A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.
We have observed them exploiting server-based N-day vulnerabilities, including the following: Ivanti Connect Secure VPN Exploitation (CVE-2023-46805 and CVE-2024-21887) A chain of exploits to bypass authentication, craft malicious requests, and execute arbitrary commands with elevated privileges.
We have observed them exploiting server-based N-day vulnerabilities, including the following: Ivanti Connect Secure VPN Exploitation (CVE-2023-46805 and CVE-2024-21887) A chain of exploits to bypass authentication, craft malicious requests, and execute arbitrary commands with elevated privileges.
The process command line contained the MSExchangePowerShellAppPool argument, indicating that the attacker exploited the Exchange server via the ProxyNotShell exploit chain... ProxyNotShell (CVE-2022-41040, CVE-2022-41082) is a related exploit chain disclosed in 2022. Both allow unauthenticated attackers to execute code on unpatched Exchange servers. | Beyond the delivery mechanism, the operation is characterized by the deployment of two distinct backdoor families, Deed RAT and Terndoor, which were utilized across three separate waves of activity.
The operation deployed two distinct backdoor families, Deed RAT and Terndoor, across different stages.
In their latest campaign, the actor leverages one of the latest WinRAR vulnerabilities that will ultimately lead to running shellcode... Rule names: EE_Loader EE_Dropper WinRAR_ADS_Traversal References / Resources: WinRAR CVE: https://nvd.nist.gov/vuln/detail/CVE-2025-8088
...exploited a public-facing Citrix NetScaler Gateway appliance, likely CVE-2023-3519, for initial access and deployed SnappyBee (also known as Deed RAT)... CVE-2023-3519 is a critical remote code execution (RCE) vulnerability in Citrix Application Delivery Controller (ADC) and Citrix Gateway appliances.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It maintains persistence by utilizing custom malware including GhostSpider, SnappyBee and the Masol remote access trojan (RAT).
Another type of previously unknown malware, which we found in a single instance in our client's infrastructure, is a modular backdoor.
In one documented intrusion, the group also deployed SNAPPYBEE and ZingDoor together, a tactic independently highlighted by Trend Micro in 2024 reporting on similar China-linked activity.
...used for DLL side-loading in connection with Deed RAT (aka Snappybee) in prior activity attributed to Salt Typhoon...
...used for DLL side-loading in connection with Deed RAT (aka Snappybee) in prior activity attributed to Salt Typhoon...
30 distinct techniques documented for this family, organized by ATT&CK tactic.
After opening an interactive remote session, they launched a PowerShell console (T1059.001 PowerShell), and within minutes, LMIGuardianSvc.exe and its associated files appeared on the system.
Start the cmd.exe process and create a thread for sending its output to C2.
Space Pirates uses legitimate-looking names when creating services.
Группа Space Pirates маскирует свое ВПО под легитимное ПО
Creating an svchost.exe process, and injecting the decompressed shellcode.
Space Pirates malware uses various algorithms to encrypt configuration data and payload.
The plugin has the functionality of a built-in sniffer that listens to the traffic of the infected computer using a raw socket.
Space Pirates malware supports multiple C2s and can update the C2 list through web pages.
Space Pirates malware uses its own protocols to communicate with the C2 server.
Space Pirates downloads additional utilities from the C2 server using the certutil tool.
Space Pirates malware can compress network messages using the LZNT1 and LZW algorithms.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-nexus remote-access backdoor in the lineage associated with BloodAlchemy. The content identifies it as FamousSparrow's primary backdoor in a separate Azerbaijani energy-targeting campaign.
A modular backdoor shared among Chinese APT groups and used by Earth Estries after initial compromise for long-term espionage and follow-on operations.
Named malware/backdoor in Salt Typhoon's server-side arsenal mentioned alongside GhostSpider, Demodex, and HemiGate.
Backdoor/RAT used by FamousSparrow in a multi-wave intrusion against an Azerbaijani oil and gas company. It was deployed via DLL sideloading using files disguised as LogMeIn Hamachi, with its payload stored in an encrypted file (.hamachi.lng), decrypted in memory using AES-128 and RC4, and persisted via a Windows service.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.