Snake Wine
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
Aliases: Ham Backdoor, Tofu Backdoor, Japanese Targets, especialmente en entornos japoneses
Snake Wine is a cyber espionage threat actor, first documented around August 2016, that is assessed to originate from China. Its primary motivation is information theft, focusing specifically on Japanese government, education, and commerce sectors. While some observations initially linked aspects of their operations to APT28, Cylance researchers, who internally track this group as 'Snake Wine,' noted discrepancies in malware used, suggesting a potential disinformation effort to obscure their true origin and methods. The group distinguishes itself through a persistent and adaptable approach, with an exclusive interest in Japanese entities, using tools like ChChes and Tofu Backdoor for long-term access and data exfiltration.
Canales, DLS e infraestructura asociada
Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.
| Tipo | Estado | Host / enlace | Title / ultimo titulo |
| DLS / leak site | unknown | www.cylance.com | Snake Wine |