ShroudedSnooper
- First seen
- 2023-09-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:07:11
Targeted industries: technology-and-telecommunications
Targeted regions: country_code:ae country_code:sa
Context
In September 2023, Cisco Talos identified a new malware family that it calls ‘HTTPSnoop’ being deployed against telecommunications providers in the Middle East. They also discovered a sister implant to 'HTTPSnoop,’ that they are naming ‘PipeSnoop,’ which can accept arbitrary shellcode from a named pipe and execute it on the infected endpoint. Based on these findings, the researchers assess with high confidence that both implants belong to a new intrusion set that it named ‘ShroudedSnooper.’
Reports & references
- Cisco Talos — Introducing Shrouded Snooper (report)
- sentinelone.com — The Israel Hamas War Cyber Domain State Sponsored Activity Of Interest (report)