SNAPPYBEE

Aliases: Deed RAT, POISONPLUG.DEED

First seen
2018-09-01 00:00:00
Malware type
rat, trojan
Family
Malware family
Last IoC activity
2026-04-28 06:39:16
Profile updated
2026-07-07 13:09:42

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:us

Context

SNAPPYBEE, also known as Deed RAT or POISONPLUG.DEED, is a Remote Access Trojan used primarily for cyber espionage activities targeting government and telecommunications sectors. Its capabilities include remote control and data exfiltration.

Reports & references

  • jsac.jpcert.or.jp — Jsac2025 1 5 Leon Chang Theo Chen En (report)
  • Trend Micro — Earth Estries (report)
  • cloud.google.com — Scatterbrain Unmasking Poisonplug Obfuscator (report)
  • rt-solar.ru — 6328 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Snappybee (report)
  • darktrace.com — Salty Much Darktraces View On A Recent Salt Typhoon Intrusion (report)

External references