TunnelSnake__2021__Operation_TunnelSnake_Securelist.pdf
ID: 63be673e-6179-4481-bf62-5066ecb7e0a6
STIX ID: report--63be673e-6179-4481-bf62-5066ecb7e0a6
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2021-05-07
Last Modified Date: 2021-05-07
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes Operation TunnelSnake, detailing the Moriya rootkit (kernel driver and user-space agent), its covert communication channel via Windows Filtering Platform, infection via public-facing servers, post-exploitation toolsets for lateral movement and data exfiltration, and multiple related tools (IISpy, BOUNCER, Earthworm, Termite). It documents targeted regional diplomatic organizations in Asia, Africa, and South Asia, timelines dating back to 2018, and discusses suspected Chinese-speaking threat actors, with numerous IOCs and indicators of compromise provided.
