Uroburos

MITRE ATT&CK: S0022 View on attack.mitre.org

Aliases: Snake, Uroburos

First seen
2003-01-01 00:00:00
Malware type
rat, rootkit
Family
Malware family
Operating systems
linux, windows, macos
Last IoC activity
2026-07-19 10:45:03
Profile updated
2026-07-07 12:43:43

Targeted industries: government-and-public-sector energy-and-utilities defense-and-aerospace

Targeted regions: country_code:us country_code:de country_code:fr country_code:ru country_code:cn

Context

Uroburos is a sophisticated cyber espionage tool written in C that has been used by units within Russia's Federal Security Service (FSB) associated with the Turla toolset to collect intelligence on sensitive targets worldwide. Uroburos has several variants and has undergone nearly constant upgrade since its initial development in 2003 to keep it viable after public disclosures. Uroburos is typically deployed to external-facing nodes on a targeted network and has the ability to leverage additional tools and TTPs to further exploit an internal network. Uroburos has interoperable implants for Windows, Linux, and macOS, employs a high level of stealth in communications and architecture, and can easily incorporate new or replacement components.

Detection coverage

  • 4 YARA rules
  • 421 Sigma rules

Malware & tools used

  • Asymmetric Cryptography (attack-pattern)
  • Reflective Code Loading (attack-pattern)
  • Native API (attack-pattern)
  • Data from Local System (attack-pattern)
  • Software Packing (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Mail Protocols (attack-pattern)
  • Junk Data (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Web Protocols (attack-pattern)
  • Multi-hop Proxy (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Hidden File System (attack-pattern)
  • Fileless Storage (attack-pattern)
  • Modify Registry (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Non-Standard Encoding (attack-pattern)
  • Query Registry (attack-pattern)
  • Inter-Process Communication (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Multi-Stage Channels (attack-pattern)
  • Protocol or Service Impersonation (attack-pattern)
  • Fallback Channels (attack-pattern)
  • Windows Service (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)

Used by threat actors

Detection rules

  • TRELLIX_ARC_Snake_Ransomware (yara-rule)
  • BLACKBERRY_Snake (yara-rule)
  • SIGNATURE_BASE_APT_MAL_RU_WIN_Snake_Malware_May23_1 (yara-rule)
  • MALPEDIA_Win_Snake_Disk_Auto (yara-rule)

Related threat objects

Reports & references

  • Kaspersky — 65545 (report)
  • CISA — Aa23 129A Snake Malware 2 (report)
  • MITRE ATT&CK — S0022 (report)

External references