Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SnowSoul

Also known as: tracked as, field, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

SnowSoul represents an evolving adversary that relies on commercial and open‑source tooling to conduct its operations. Core capabilities include the use of the PlugX RAT family for remote access, exploitation of third‑party cloud accounts and web services for command and control as well as exfiltration, and manipulation of privileged configurations to achieve temporary elevation. The actor demonstrates a sophisticated understanding of modern enterprise environments, targeting Microsoft Exchange, Office 365, Gmail, Dropbox and related platforms to harvest credentials or service tokens. Once inside, SnowSoul often launches endpoint denial‑of‑service attacks against email, DNS, or web infrastructure, blurs its traffic with spoofed browser and system attributes, and injects malicious container images (AWS AMIs, GCP containers, Azure images) for persistence. Defensive tactics combine credential theft, automated scanning, polymorphic code transformations, and the hijacking of service binaries to maintain an elevated foothold while evading detection systems. The adversary also attempts to intercept or bypass MFA mechanisms, thereby expanding its reach across organizational perimeters.

Goals & Targeting

Targeted Sectors

Financial services
Media
Government
Defense
Telecommunications
Food agriculture
Energy
Critical infrastructure
Information technology
Manufacturing

Targeted Countries / Regions

CN
KP

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

SnowSoul is a financially motivated threat actor that has been active since early 2026, primarily targeting Chinese organizations. The group runs low‑ransom extortion campaigns and leaks stolen data when victims refuse to pay.

Goals & Targeting

SnowSoul’s primary strategic objective is monetary gain through extortion and data monetization. By embedding themselves in critical services like Exchange and cloud storage, they seek to maximize leverage over victims, forcing a ransom payment or offering leaked data at a public forum. Their targeting profile spans the financial‑services, media, government, defense, telecommunications, food‑agriculture, energy, critical infrastructure, IT, and manufacturing sectors within China (CN) and North Korea (KP), focusing on organizations with high external exposure to cloud services. The pattern of using serial identifiers for distinct attacks indicates a disciplined campaign that prefers consistent monetization cycles rather than opportunistic strikes. SnowSoul’s operations are designed to generate quick revenue while remaining stealthy, leveraging legitimate‑looking infrastructure to blend in with normal business traffic.

Enhanced Description

Key Capabilities

  • Remote Access Trojans (PlugX)
  • Financially motivated campaigns
  • Compromise third‑party cloud accounts and web services for command & control and exfiltration
  • Abuse privileged access configurations for temporary elevation
  • Target Exchange, Office 365, Google Workspace to acquire credentials or service tokens
  • Execute endpoint denial‑of‑service attacks on email, DNS, web, and other network services
  • Create legitimate‑appearing email and cloud accounts for staging
  • Exploit software vulnerabilities in remote services for unauthorized access and lateral movement
  • Hijack service binaries by modifying permissions to execute malicious payloads with elevated privileges
  • Implant backdoored or malicious container images (AWS AMIs, GCP containers, Azure images) for persistence
  • Spoof browser and system attributes to blend in traffic
  • Target MFA mechanisms to intercept credentials
  • Perform network denial‑of‑service attacks for disruption or diversion
  • Use polymorphic and metamorphic code to evade detection

MITRE ATT&CK Tactics

Initial Access
Credential Access
Privilege Escalation
Command and Control
Exfiltration
Discovery
Lateral Movement
Execution
Persistence
Defense Evasion
Impact

ATT&CK Techniques

T1037
T1557
T1583
T1592
T1123
T1547
T1119
T1115
T1071
T1140
T1567
T1010
T1560
T1185
T1112
T1580
T1217
T1092
T1595
T1548
T1087
T1059
T1020
T1083
T1612
T1586
T1619
T1041
T1554
T1098
T1110
T1531
T1671
T1197
T1132
T1650
T1651
T1134
T1526
T1538
T1021
T1102.001
T1048.004
T1566
T1078
T1078.002
T1133
T1499
T1566.001
T1547.003
T1570
T1064
T1161
T1027

Software / Tooling

PlugX
InvisibleFerret
BeaverTail
Bumblebee
ZLib
netsh
HTRN
Havex RAT
Web Shell
PowerShell
Dark
Hook
SNOWLIGHT
Systemd
rundll32
MSBuild
BITS
WildFire

Campaigns & Victims

SnowSoul’s campaigns exhibit a serial, systematic approach with uniquely numbered identifiers (e.g., ID‑1265, ID‑1270). The actor frequently attacks Chinese enterprises across several sectors but also shows potential cross‑border tactics involving North Korean entities. Recent operations focus on low‑ransom extortion (~$2,000) and subsequent data leakage when demands are not met. SnowSoul leverages cloud infrastructure both as a staging area for malicious payloads and as a covert exfiltration channel, often using compromised email or storage accounts to conceal traffic from security teams. Operational tempo appears quarterly to semi‑annual with periods of inactivity likely used for reconnaissance or lateral movement consolidation. Impact tactics include denial‑of‑service attacks against key services such as Exchange, DNS, or web portals, aimed at forcing victims into a faster ransom decision or distracting them while data is exfiltrated. Notable past operations are documented in reports from early 2026 targeting multiple Chinese companies with similar extortion and leak patterns. The group’s use of publicly available tools (e.g., PlugX) and legitimate cloud services indicates a preference for low‑risk, high‑reward attacks rather than zero‑day exploits alone.

IOC Patterns

  • domain
  • file
  • ip-v4
  • hash-sha256

Recommended Actions

  • Enforce least privilege with just‑in‑time controls to limit temporary elevation of accounts;
  • Require MFA (and continuous authentication) for all privileged and third‑party cloud accounts;
  • Monitor outbound traffic for anomalous use of web services (Gmail, Dropbox, Cloudflare Workers) that may signal exfiltration;
  • Implement detection rules for PlugX RAT behaviors including registry key changes, binary injection, and service hijacking;
  • Strictly control permissions on Windows service binaries and monitor for unauthorized modifications;
  • Detect and alert on anomalous account creation patterns, especially in email and cloud services;
  • Deploy rate‑limiting, scrubbing, or IP reputation filtering to mitigate DoS traffic against critical web/DNS/email services;
  • Enforce image signing and integrity verification for container images before deployment;
  • Use endpoint detection platforms that monitor service hijack attempts and binary replacements;
  • Employ behavioral analytics to detect spoofed user‑agent strings, system attributes, and polymorphic/mutating code signatures;
  • Implement ongoing vulnerability scanning of remote services and patch management to reduce exploitation likelihood;
  • Maintain an updated inventory of known malicious files (hashes) for active blocking in firewalls and intrusion prevention systems

Suggested Tags

financial-motivated
PlugX_RAT
cloud_account_compromise
web_service_exfiltration
account-creation
cloud-storage-exfiltration
denial-of-service
phishing
credential-access
service-hijacking
malicious-image
obfuscation
exploitation
persistence
MFA_bypass
network_DDoS
polymorphic-malware
defense-evasion
remote-access-trojan
exchange-targeting

Confidence Assessment

The evidence for SnowSoul’s existence and tactics is moderate to high, based primarily on independent reports, observed malware samples (PlugX RAT), and documented campaign identifiers. However, the actor’s exact origins, organizational backing, and full operational coverage remain unclear, as many data points are anecdotal or derived from a single nation‑state focus. Gaps exist regarding the long‑term persistence mechanisms in cloud environments, the extent of lateral movement within victim networks, and detailed attribution to state actors versus non‑state. Continuous monitoring for new indicators of compromise will refine confidence levels over time.

ATT&CK Techniques

Defense impairment
1 technique
Privilege Escalation
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 15 IPv4 Address 1 Filename 1 Domain 3

References

  1. attack.mitre.org — Cited by web research for: services
  2. unit42.paloaltonetworks.com — Cited by web research for: BeaverTail
  3. www.fortinet.com — Cited by web research for: Keyloggers
  4. attack.mitre.org — Cited by web research for: Process Hollowing
  5. www.brinztech.com — Cited by web research for: WhatsApp
  6. https://malpedia.caad.fkie.fraunhofer.de/details/win.plugx — Cited by AI analysis.
  7. https://torwire.com/news/cybersecurity/snowsoul-attack-chinese-organizations-data-leak/ — Cited by AI analysis.
  8. https://malpedia.caad.fkie.fraunhofer.de/actor/snowsoul — Cited by AI analysis.

Intel Summary

54

Techniques

45

Tools

0

Campaigns

39

IOCs

0

Observed Data

16

Tactics

Tags

Data Exfiltration
APT
Extortion
China-focused
Ransomware
Data Leak
financial-motivated
PlugX_RAT
cloud_account_compromise
web_service_exfiltration
account-creation
cloud-storage-exfiltration
denial-of-service
phishing
credential-access
service-hijacking
malicious-image
obfuscation
exploitation
persistence
MFA_bypass
network_DDoS
polymorphic-malware
defense-evasion
remote-access-trojan
exchange-targeting

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.