Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Snake Wine

Description

**Targets:** Japanese Targets **Toolset/Malware:** Ham Backdoor, Tofu Backdoor **Notes:** Tracked by Cylance

Goals & Targeting

Targeted Countries / Regions

JP

AI Analysis

· 1 week ago

Executive Summary

Snake Wine is a nation-state threat actor primarily involved in espionage activities targeting Japan. Known for deploying sophisticated malware such as Ham Backdoor and Tofu Backdoor, Snake Wine has demonstrated persistent operations since at least 2019. Their activities pose significant risks to Japanese governmental and private sector entities.

Goals & Targeting

Snake Wine's strategic objectives appear to be centered around espionage, with a focus on targeting Japanese entities for intelligence collection. Given Japan's geopolitical significance, they are likely interested in information related to government operations, defense, and possibly private sector technology or business strategies. The actor's targeting profile focuses exclusively on Japan, suggesting either a state-affiliated operation with specific regional interests or a group with operational constraints limiting their reach.

Enhanced Description

Snake Wine is a nation-state threat actor with a primary focus on espionage. Targeting predominantly Japan, Snake Wine has been active for several years, first identified in early 2019 and last observed in late 2019, according to reports. Their activities involve the deployment of malware families such as Ham Backdoor and Tofu Backdoor, which are used for persistence and data collection purposes. These tools suggest a capability to maintain long-term access to targeted systems while gathering sensitive information. The actor's operations have been tracked by security firm Cylance, indicating their ongoing presence in the threat landscape.

Key Capabilities

  • Malware development (Ham Backdoor, Tofu Backdoor)
  • Persistence mechanisms
  • Data exfiltration capabilities
  • Network communication tools

MITRE ATT&CK Tactics

Initial Access
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1059
T1078
T1566.004
T1572
T1203.001
T1018
T1133
T1220

Software / Tooling

Ham Backdoor
Tofu Backdoor
Custom C2 infrastructure

Campaigns & Victims

Snake Wine has demonstrated a consistent pattern of targeting Japanese entities, with campaigns likely tied to specific Intelligence Requirements (_REQs) or internal priorities. Their use of custom malware suggests a capability for tailored attacks aimed at maintaining stealth and persistence in targeted networks. Notable operations include early activity observed in 2019 with initial sightings of the Tofu Backdoor and subsequent evolution in their toolset.

IOC Patterns

  • Specific file hashes associated with Ham Backdoor and Tofu Backdoor
  • Registry entries for persistence mechanisms
  • Network communication patterns indicative of command-and-control (C2) infrastructure

Recommended Actions

  • Monitor network traffic for signs of C2 activity related to known Snake Wine TTPs.
  • Patch systems against potential vulnerabilities exploited by these malware families.
  • Train users to recognize phishing attempts, as initial access may involve social engineering.
  • Implement robust endpoint detection and response (EDR) solutions to detect malicious processes.
  • Conduct regular backups of critical systems to mitigate potential data loss from persistent threats.
  • Perform active threat hunting for signs of Snake Wine's tools in the network environment.
  • Analyze logs for unusual activity, such as unexpected processes or file modifications.

Suggested Tags

nation-state
APT
Japan
espionage
malware

Confidence Assessment

High confidence in the actor's APT nature and targeting of Japan is derived from consistent reporting and malware analysis. However, limited visibility into their operational infrastructure and origin poses some uncertainty.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

2

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
nation-state
Japan
espionage
malware

Details

Type
Nation-State
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.