Uptime Hamster: 10d 18h 2mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Snake Wine

Snake Wine

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: Ham Backdoor, Tofu Backdoor, Japanese Targets, especialmente en entornos japoneses
Ver en IntelTracker → APTTrail →
Snake Wine is a cyber espionage threat actor, first documented around August 2016, that is assessed to originate from China. Its primary motivation is information theft, focusing specifically on Japanese government, education, and commerce sectors. While some observations initially linked aspects of their operations to APT28, Cylance researchers, who internally track this group as 'Snake Wine,' noted discrepancies in malware used, suggesting a potential disinformation effort to obscure their true origin and methods. The group distinguishes itself through a persistent and adaptable approach, with an exclusive interest in Japanese entities, using tools like ChChes and Tofu Backdoor for long-term access and data exfiltration.

Aliases del actor

Ham BackdoorTofu BackdoorJapanese Targetsespecialmente en entornos japoneses

Actores similares

backdoordiplomacyactor · 2capi-backdooractor · 1BackdoorDiplomacyapt · 1snake-wineactor · 1Abrahams_Axactor · 2apt-bahamutactor · 1apt-shamoonactor · 1smokedhamactor · 1blacksnakeactor · 1shamoonactor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownwww.cylance.comSnake Wine
Motivacion