Uroburos (Windows)
Aliases: Snake
- Malware type
- rootkit
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:29:31
- Profile updated
- 2026-07-07 12:43:40
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:ua country_code:ru country_code:us
Context
Uroburos is a driver for Windows, including a bypass of PatchGuard. According to Andrzej Dereszowski and Matthieu Kaczmarek, "the techniques used demonstrate [their] excellent knowledge of Windows kernel internals."
Detection coverage
- 4 YARA rules
Detection rules
- MALPEDIA_Win_Snake_Disk_Auto (yara-rule)
- TRELLIX_ARC_Snake_Ransomware (yara-rule)
- BLACKBERRY_Snake (yara-rule)
- SIGNATURE_BASE_APT_MAL_RU_WIN_Snake_Malware_May23_1 (yara-rule)
Related threat objects
- Uroburos (malware)
Reports & references
- circl.lu — Tr 25 (report)
- Kaspersky — The Epic Turla Operation (report)
- nccgroup.trust — Turla Png Dropper Is Back (report)
- secureworks.com — Iron Hunter (report)
- exatrack.com — Tricephalic Hellkeeper (report)
- crysys.hu — Ukatemicrysys Territorialdispute (report)
- artemonsecurity.com — Snake Whitepaper (report)
- CISA — Aa23 129A (report)
- gdatasoftware.com — 23937 The Uroburos Case New Sophisticated Rat Identified (report)
- gdatasoftware.com — 23941 Com Object Hijacking The Discreet Way Of Persistence (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Uroburos (report)
- gdatasoftware.com — 23968 Uroburos Highly Complex Espionage Software With Russian Roots (report)
- research.nccgroup.com — Turla Png Dropper Is Back (report)
- gdatasoftware.com — 23966 Uroburos Deeper Travel Into Kernel Protection Mitigation (report)
- gdatasoftware.com — 23953 Analysis Of Uroburos Using Windbg (report)
- gdatasoftware.com — 23958 Uroburos Rootkit Belgian Foreign Ministry Stricken (report)
- artemonsecurity.com — Uroburos (report)
- carbonblack.com — Threat Analysis Carbon Black Threat Research Dissects Png Dropper (report)
- exatrack.com — Uroburos En (report)