Snugy is a PowerShell-based backdoor associated with the xHunt espionage campaign and assessed to be a variant of the CASHY200 backdoor family. It has been used in intrusions targeting organizations in Kuwait, including government, shipping, and transportation environments, and has been observed on compromised Microsoft Exchange infrastructure as part of long-term persistence operations.
Snugy provides remote command execution and basic host identification functionality. Observed behavior includes obtaining the victim system hostname, executing attacker-supplied commands, and exfiltrating command output. Its command-and-control channel uses DNS tunneling, with the malware issuing crafted DNS A-record lookups to actor-controlled infrastructure and interpreting responses to determine whether to transmit host information or execute commands. This covert communications design helps blend malicious traffic into routine name-resolution activity.
In observed xHunt operations, Snugy was deployed as a PowerShell script and persisted through scheduled tasks configured to run at regular intervals with execution-policy bypass. The task names were chosen to resemble legitimate Windows components, indicating deliberate masquerading for defense evasion and persistence. Snugy has been used alongside other xHunt tooling, including the TriFive PowerShell backdoor and the BumbleBee webshell, as part of broader post-compromise activity on Exchange and IIS servers.
Snugy fits xHunt’s pattern of maintaining durable access through lightweight PowerShell implants, covert command channels, and operational blending with legitimate administrative and system behavior. Its role in these intrusions is consistent with espionage-oriented post-exploitation, enabling sustained remote access and collection from compromised Windows servers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The OfficeIntegrator.ps1 file seen in the ResolutionHosts task is a PowerShell-based backdoor we call Snugy, which allows an actor to obtain the system's hostname and to run commands. Snugy is a variant of the CASHY200 backdoor used by actors in previous attacks in the xHunt campaign.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
On Aug. 28 and Oct. 22, 2019, the actors created the ResolutionHosts and ResolutionsHosts tasks to run two separate PowerShell-based backdoors. The actors used these two scheduled tasks as a persistence method, as they ran the two PowerShell scripts repeatedly, albeit at different intervals.
On Aug. 28 and Oct. 22, 2019, the actors created the ResolutionHosts and ResolutionsHosts tasks to run two separate PowerShell-based backdoors. The actors used these two scheduled tasks as a persistence method, as they ran the two PowerShell scripts repeatedly, albeit at different intervals.
This investigation resulted in the discovery of two new backdoors called TriFive and Snugy... as well as a new webshell that we call BumbleBee... The actor used the BumbleBee webshell to upload and download files to and from the compromised Exchange server, but more importantly, to run commands that the actor used to discover additional systems and to move laterally to other servers on the network.
On Aug. 28 and Oct. 22, 2019, the actors created the ResolutionHosts and ResolutionsHosts tasks to run two separate PowerShell-based backdoors. The actors used these two scheduled tasks as a persistence method, as they ran the two PowerShell scripts repeatedly, albeit at different intervals.
Both of the backdoors installed on the compromised Exchange server of a Kuwait government organization used covert channels for C2 communications, specifically DNS tunneling and an email-based channel using drafts in the Deleted Items folder of a compromised email account.
We did observe the threat actors using the Snugy tool to run commands and exfiltrate the results, as we were able to obtain the domains queried via ping requests sent from the compromised server. Based on the exfiltrated data from within the subdomains, we were able to determine the actors ran ipconfig /all and dir.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PowerShell-based backdoor deployed by xHunt APT, leveraging scheduled tasks for persistence and using Exchange Web Services for C2 communication.
PowerShell backdoor (variant of CASHY200) used for persistent access; commonly executed via scheduled tasks (e.g., OfficeIntegrator.ps1 / xpsrchvw.ps1) with execution-policy bypass.
A backdoor newly discovered during investigation of the xHunt campaign at Kuwaiti organizations. The provided content mentions its discovery but does not describe its functionality further.
A PowerShell backdoor and variant of CASHY200 that uses DNS tunneling for command and control. It issues crafted DNS A-record lookups to actor-controlled domains, can beacon, send hostnames, receive commands, execute them via cmd /c, and exfiltrate results one byte at a time through subdomains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.