Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TunnelSnake

Description

The TunnelSnake campaign demonstrates the activity of a sophisticated actor that invests significant resources in designing an evasive toolset and infiltrating networks of high-profile organizations. By leveraging Windows drivers, covert communications channels and proprietary malware, the group behind it maintains a considerable level of stealth. That said, some of its TTPs, like the usage of a commodity webshell and open-source legacy code for loading unsigned drivers, may get detected and in fact were flagged by Kaspersky's product, giving them visibility into the group’s operation.

AI Analysis

· 1 week ago

Executive Summary

TunnelSnake is a sophisticated cyber threat actor known for its evasive tactics and use of custom tools to infiltrate high-profile organizations. The group leverages Windows drivers, covert communication channels, and proprietary malware to maintain operational stealth. Despite some less sophisticated TTPs, such as the use of a commodity webshell and open-source legacy code, TunnelSnake demonstrates a high level of technical proficiency.

Goals & Targeting

TunnelSnake appears to focus on high-profile organizations across multiple sectors, likely with the intent of conducting long-term espionage or data exfiltration. The group's targeting suggests a strategic interest in sensitive information and operational persistence. Its victims are typically large enterprises or critical infrastructure entities that provide high-value targets for intelligence gathering or disruption.

Enhanced Description

TunnelSnake operates with a degree of sophistication, investing significant resources into developing an evasive toolset. The group is known to target high-profile organizations across various sectors, using Windows drivers, covert communication channels, and proprietary malware to infiltrate networks. Notably, TunnelSnake's use of unsigned drivers loaded via open-source legacy code has been detected by security products like Kaspersky's. While the group employs some less sophisticated tactics, such as leveraging a commodity webshell, these have also provided opportunities for detection. The actor's ability to maintain stealth while deploying advanced tools underscores its technical capabilities and persistent threat profile.

Key Capabilities

  • Windows driver manipulation
  • Covert communication channels
  • Proprietary malware development
  • Evasion of detection mechanisms
  • Leverage of commodity webshells

MITRE ATT&CK Tactics

Lateral Movement
Exfiltration
Persistence
Credential Access
Reconnaissance

ATT&CK Techniques

T1071.004
T1569.002
T1055
T1036
T1003

Software / Tooling

Custom malware
Commodity webshell
Unsigned drivers

Campaigns & Victims

TunnelSnake has demonstrated a patient and methodical approach to infiltration, with campaigns persisting over significant periods. The actor's use of custom tools alongside off-the-shelf components suggests an effort to balance stealth with operational efficiency. Notable past operations include targeting critical infrastructure and large corporate entities, where the group has achieved initial access through spear-phishing or supply chain compromises.

IOC Patterns

  • Usage of Windows drivers signed by untrusted certificates
  • Covert communication via domain fronting or hidden channels
  • Presence of commodity webshells in infected systems
  • Indicator of Compromise (IOC) patterns linked to Kaspersky detection events

Recommended Actions

  • Implement robust endpoint detection and response (EDR) solutions to monitor for custom malware activity.
  • Conduct regular audits of signed binaries and drivers on systems to identify unauthorized unsigned drivers.
  • Enforce strict least privilege policies to mitigate the impact of compromised credentials.
  • Monitor network traffic for signs of covert communication channels, such as unusual DNS queries or HTTP requests.

Suggested Tags

APT
Cyber Espionage
Targeted Intrusion
High-Profile Organisations

Confidence Assessment

Moderate confidence in the data due to limited publicly available details about TunnelSnake's origins and specific campaigns. While some TTPs are known, more information on its long-term goals and exact targeting criteria would improve situational awareness.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
APT
Cyber Espionage
Targeted Intrusion
High-Profile Organisations

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.