TunnelSnake
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
TunnelSnake is a state-sponsored cyber espionage group assessed with high confidence to be of Chinese origin. The group first emerged with documented activity in October 2019, focusing its operations on governmental and diplomatic entities in Asia and Africa. Their primary motivation is to steal sensitive information through long-term infiltration. What notably distinguishes TunnelSnake from other actors is its extensive reliance on the highly evasive Moriya rootkit, a custom-developed kernel-mode malware designed for covert command and control, allowing them to remain undetected within compromised networks for extended periods. The group is primarily known by the name TunnelSnake and does not have widely recognized aliases or common confusions with other unrelated threat actors.
Sectores objetivo (SOCRadar)
Space & DefenseNational Security&International Affairs