TunnelSnake is a sophisticated threat actor targeting high-profile organizations using Windows drivers, stealthy channels, and proprietary malware.
Analyst brief
TunnelSnake is a sophisticated and stealthy threat actor targeting high-profile organizations. It employs Windows drivers, covert communication channels, and proprietary malware to infiltrate networks while maintaining a low profile. Its key TTPs include the use of open-source legacy code for loading unsigned drivers and a commodity webshell, which have been leveraged for detection visibility. Defenders should focus on monitoring for anomalous driver loads, unusual C2 communications, and known webshell signatures.
TunnelSnake
unknown
The TunnelSnake campaign demonstrates the activity of a sophisticated actor that invests significant resources in designing an evasive toolset and infiltrating networks of high-profile organizations. By leveraging Windows drivers, covert communications channels and proprietary malware, the group behind it maintains a considerable level of stealth. That said, some of its TTPs, like the usage of a commodity webshell and open-source legacy code for loading unsigned drivers, may get detected and in fact were flagged by Kaspersky's product, giving them visibility into the group’s operation.
What are the primary techniques TunnelSnake uses to infiltrate networks?+
TunnelSnake infiltrates networks by employing Windows drivers, covert communication channels, and proprietary malware. Additionally, it uses TTPs such as open-source legacy code for loading unsigned drivers and a commodity webshell.
What should defenders focus on to detect TunnelSnake's activity?+
Defenders should focus on monitoring for anomalous driver loads, unusual C2 communications, and known webshell signatures.