SnappyTCP

S1163

Malware.View on attack.mitre.org

About this malware

SnappyTCP is a web shell used by Sea Turtle between 2021 and 2023 against multiple victims. SnappyTCP appears to be based on a public GitHub project that has since been removed from the code-sharing site. SnappyTCP includes a simple reverse TCP shell for Linux and Unix environments with basic command and control capabilities.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1059.004
Unix Shell

SnappyTCP creates the reverse shell using a pthread spawning a bash shell.

T1071.001
Web Protocols

SnappyTCP connects to the command and control server via a TCP socket using HTTP.

T1095
Non-Application Layer Protocol

SnappyTCP spawns a reverse TCP shell following an HTTP-based negotiation.

T1505.003
Web Shell

SnappyTCP is a reverse TCP shell with command and control capabilities used for persistence purposes.

T1573.002
Asymmetric Cryptography

SnappyTCP can use OpenSSL and TLS certificates to encrypt traffic.

Groups that use it1

Campaigns0

None recorded.

References1

  1. PWC Sea Turtle 2023 Open source
    PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.