SnappyTCP

MITRE ATT&CK: S1163 View on attack.mitre.org

Aliases: SnappyTCP

Malware type
webshell
Family
Malware family
Operating systems
linux
Profile updated
2026-07-07 13:19:02

Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications

Targeted regions: country_code:dk country_code:cy country_code:tr

Context

SnappyTCP is a web shell used by Sea Turtle between 2021 and 2023 against multiple victims. SnappyTCP appears to be based on a public GitHub project that has since been removed from the code-sharing site. SnappyTCP includes a simple reverse TCP shell for Linux and Unix environments with basic command and control capabilities.

Detection coverage

  • 2 YARA rules
  • 72 Sigma rules

Malware & tools used

  • Unix Shell (attack-pattern)
  • Web Protocols (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Web Shell (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Apt_Tealkurma_Snappytcp_Strings (yara-rule)
  • SEKOIA_Apt_Tealkurma_Snappytcp_Reverse_Shell_Strings (yara-rule)

Reports & references

  • huntandhackett.com — Turkish Espionage Campaigns (report)
  • pwc.com — Tortoise And Malwahare (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Snappy Tcp (report)
  • blog.strikeready.com — Pivoting Through A Sea Of Indicators To Spot Turtles (report)
  • MITRE ATT&CK — S1163 (report)

External references