SnappyTCP
MITRE ATT&CK: S1163 View on attack.mitre.org
Aliases: SnappyTCP
- Malware type
- webshell
- Family
- Malware family
- Operating systems
- linux
- Profile updated
- 2026-07-07 13:19:02
Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications
Targeted regions: country_code:dk country_code:cy country_code:tr
Context
SnappyTCP is a web shell used by Sea Turtle between 2021 and 2023 against multiple victims. SnappyTCP appears to be based on a public GitHub project that has since been removed from the code-sharing site. SnappyTCP includes a simple reverse TCP shell for Linux and Unix environments with basic command and control capabilities.
Detection coverage
- 2 YARA rules
- 72 Sigma rules
Malware & tools used
- Unix Shell (attack-pattern)
- Web Protocols (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Web Shell (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
Used by threat actors
- Sea Turtle (threat-actor)
Detection rules
- SEKOIA_Apt_Tealkurma_Snappytcp_Strings (yara-rule)
- SEKOIA_Apt_Tealkurma_Snappytcp_Reverse_Shell_Strings (yara-rule)
Reports & references
- huntandhackett.com — Turkish Espionage Campaigns (report)
- pwc.com — Tortoise And Malwahare (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Snappy Tcp (report)
- blog.strikeready.com — Pivoting Through A Sea Of Indicators To Spot Turtles (report)
- MITRE ATT&CK — S1163 (report)