Uroburos
MITRE ATT&CK: S0022 View on attack.mitre.org
Aliases: Snake, Uroburos
- First seen
- 2003-01-01 00:00:00
- Malware type
- rat, rootkit
- Family
- Malware family
- Operating systems
- linux, windows, macos
- Last IoC activity
- 2026-07-19 10:45:03
- Profile updated
- 2026-07-07 12:43:43
Targeted industries: government-and-public-sector energy-and-utilities defense-and-aerospace
Targeted regions: country_code:us country_code:de country_code:fr country_code:ru country_code:cn
Context
Uroburos is a sophisticated cyber espionage tool written in C that has been used by units within Russia's Federal Security Service (FSB) associated with the Turla toolset to collect intelligence on sensitive targets worldwide. Uroburos has several variants and has undergone nearly constant upgrade since its initial development in 2003 to keep it viable after public disclosures. Uroburos is typically deployed to external-facing nodes on a targeted network and has the ability to leverage additional tools and TTPs to further exploit an internal network. Uroburos has interoperable implants for Windows, Linux, and macOS, employs a high level of stealth in communications and architecture, and can easily incorporate new or replacement components.
Detection coverage
- 4 YARA rules
- 421 Sigma rules
Malware & tools used
- Asymmetric Cryptography (attack-pattern)
- Reflective Code Loading (attack-pattern)
- Native API (attack-pattern)
- Data from Local System (attack-pattern)
- Software Packing (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Mail Protocols (attack-pattern)
- Junk Data (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Web Protocols (attack-pattern)
- Multi-hop Proxy (attack-pattern)
- Windows Command Shell (attack-pattern)
- Hidden File System (attack-pattern)
- Fileless Storage (attack-pattern)
- Modify Registry (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Non-Standard Encoding (attack-pattern)
- Query Registry (attack-pattern)
- Inter-Process Communication (attack-pattern)
- System Information Discovery (attack-pattern)
- Multi-Stage Channels (attack-pattern)
- Protocol or Service Impersonation (attack-pattern)
- Fallback Channels (attack-pattern)
- Windows Service (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
Used by threat actors
- Turla (threat-actor)
Detection rules
- TRELLIX_ARC_Snake_Ransomware (yara-rule)
- BLACKBERRY_Snake (yara-rule)
- SIGNATURE_BASE_APT_MAL_RU_WIN_Snake_Malware_May23_1 (yara-rule)
- MALPEDIA_Win_Snake_Disk_Auto (yara-rule)
Related threat objects
- Uroburos (Windows) (malware)
Reports & references
- Kaspersky — 65545 (report)
- CISA — Aa23 129A Snake Malware 2 (report)
- MITRE ATT&CK — S0022 (report)