TunnelSnake
- First seen
- 2020-04-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:10:32
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Targeted regions: country_code:us country_code:gb country_code:de
Context
The TunnelSnake campaign demonstrates the activity of a sophisticated actor that invests significant resources in designing an evasive toolset and infiltrating networks of high-profile organizations. By leveraging Windows drivers, covert communications channels and proprietary malware, the group behind it maintains a considerable level of stealth. That said, some of its TTPs, like the usage of a commodity webshell and open-source legacy code for loading unsigned drivers, may get detected and in fact were flagged by Kaspersky's product, giving them visibility into the group’s operation.
Reports & references
- redpacketsecurity.com — Operation Tunnelsnake (report)
- Kaspersky — 101831 (report)