216.73.217.22

New version of MysterySnail RAT and lightweight MysteryMonoSnail backdoor

· Published 17/04/2025 13:06 · Modified 17/04/2025 15:09

Export JSON

Essential information

Published
17/04/2025 13:06
Modified
17/04/2025 15:09
Tags
2025-04-17 apt ironhusky mysterymonosnail mysterysnail
Related entities
1 vulnerabilities (cve), 2 observables, 1 intrusion sets (apt), 10 techniques (mitre), 2 malware, 3 others

Description

A new version of the RAT, attributed to the Chinese-speaking group, has been detected targeting government organizations in Mongolia and Russia. The malware, which hadn't been publicly reported since 2021, now features a modular architecture with five additional DLL modules for command execution. A lightweight version dubbed was also observed. The infection chain involves a malicious MMC script, an intermediary backdoor, and the main RAT payload. The attackers use public file storage and the piping-server project for command and control. This case highlights the importance of maintaining vigilance against seemingly obsolete malware families, as they may continue operating undetected for extended periods.

External references