**Targets:** Japanese Targets **Toolset/Malware:** Ham Backdoor, Tofu Backdoor **Notes:** Tracked by Cylance
Targeted Countries / Regions
Executive Summary
Snake Wine is a nation-state threat actor primarily involved in espionage activities targeting Japan. Known for deploying sophisticated malware such as Ham Backdoor and Tofu Backdoor, Snake Wine has demonstrated persistent operations since at least 2019. Their activities pose significant risks to Japanese governmental and private sector entities.
Goals & Targeting
Snake Wine's strategic objectives appear to be centered around espionage, with a focus on targeting Japanese entities for intelligence collection. Given Japan's geopolitical significance, they are likely interested in information related to government operations, defense, and possibly private sector technology or business strategies. The actor's targeting profile focuses exclusively on Japan, suggesting either a state-affiliated operation with specific regional interests or a group with operational constraints limiting their reach.
Enhanced Description
Snake Wine is a nation-state threat actor with a primary focus on espionage. Targeting predominantly Japan, Snake Wine has been active for several years, first identified in early 2019 and last observed in late 2019, according to reports. Their activities involve the deployment of malware families such as Ham Backdoor and Tofu Backdoor, which are used for persistence and data collection purposes. These tools suggest a capability to maintain long-term access to targeted systems while gathering sensitive information. The actor's operations have been tracked by security firm Cylance, indicating their ongoing presence in the threat landscape.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Snake Wine has demonstrated a consistent pattern of targeting Japanese entities, with campaigns likely tied to specific Intelligence Requirements (_REQs) or internal priorities. Their use of custom malware suggests a capability for tailored attacks aimed at maintaining stealth and persistence in targeted networks. Notable operations include early activity observed in 2019 with initial sightings of the Tofu Backdoor and subsequent evolution in their toolset.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the actor's APT nature and targeting of Japan is derived from consistent reporting and malware analysis. However, limited visibility into their operational infrastructure and origin poses some uncertainty.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
2
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics