Snake, also known as Uroburos, is a sophisticated cyberespionage implant and kernel-mode rootkit developed and operated by the Russian state-affiliated Turla group, also known as Venomous Bear and Waterbug. It supports long-term persistence, covert control of compromised systems, arbitrary command execution, file theft, and network-traffic capture. It targets Microsoft Windows and supports both 32-bit and 64-bit systems. Its use has been documented in espionage against government institutions.
The malware combines a kernel driver with an encrypted virtual file system and uses a modular architecture that supports additional functionality. Peer-to-peer communication enables operators to control compromised machines through other infected hosts and relay stolen information to an Internet-connected system. This architecture supports operations within segmented networks, including systems without direct Internet access, and facilitates compromise of additional machines within a network.
Snake employs kernel-level defense evasion, including abuse of a vulnerable VirtualBox driver to disable Windows Driver Signature Enforcement and PatchGuard, permitting unsigned malicious drivers to load while undermining kernel integrity protections. Its initial infection vector is not established. Snake/Uroburos is distinct from the unrelated EKANS ransomware and the .NET-based Snake credential stealer and keylogger.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The first type of downloader we’ve seen used to deploy Snake are RTF documents containing the well-known Microsoft Office Equation Editor exploit (CVE-2017-11882). | Snake is a modular .NET keylogger and credential stealer first spotted in late November 2020.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Snake is an implant developed and used by the Russian state-affiliated APT group Turla (aka. Venomous Bear, Waterbug). Snake is used to establish long-term persistence on victim devices and stealthily exfiltrate sensitive data.
Les victimes étaient des entités ministérielles, visées par exemple en 2014 par le code malveillant Uroburos.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
71 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
103 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A keylogger and information stealer.
Russian malware used against Ukrainian government systems in the context of pre-invasion cyber espionage and disruption.
A sophisticated long-term cyberespionage implant used for covert access, persistence, and strategic intelligence collection.
Ransomware family mentioned as targeting healthcare and medical facilities during the COVID period.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.