SNAPPYBEE
Aliases: Deed RAT, POISONPLUG.DEED
- First seen
- 2018-09-01 00:00:00
- Malware type
- rat, trojan
- Family
- Malware family
- Last IoC activity
- 2026-04-28 06:39:16
- Profile updated
- 2026-07-07 13:09:42
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:us
Context
SNAPPYBEE, also known as Deed RAT or POISONPLUG.DEED, is a Remote Access Trojan used primarily for cyber espionage activities targeting government and telecommunications sectors. Its capabilities include remote control and data exfiltration.
Reports & references
- jsac.jpcert.or.jp — Jsac2025 1 5 Leon Chang Theo Chen En (report)
- Trend Micro — Earth Estries (report)
- cloud.google.com — Scatterbrain Unmasking Poisonplug Obfuscator (report)
- rt-solar.ru — 6328 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Snappybee (report)
- darktrace.com — Salty Much Darktraces View On A Recent Salt Typhoon Intrusion (report)