logo

TunnelSnake__2021__Operation_TunnelSnake_Securelist.pdf

ID: 63be673e-6179-4481-bf62-5066ecb7e0a6

STIX ID: report--63be673e-6179-4481-bf62-5066ecb7e0a6

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2021-05-07

Last Modified Date: 2021-05-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes Operation TunnelSnake, detailing the Moriya rootkit (kernel driver and user-space agent), its covert communication channel via Windows Filtering Platform, infection via public-facing servers, post-exploitation toolsets for lateral movement and data exfiltration, and multiple related tools (IISpy, BOUNCER, Earthworm, Termite). It documents targeted regional diplomatic organizations in Asia, Africa, and South Asia, timelines dating back to 2018, and discusses suspected Chinese-speaking threat actors, with numerous IOCs and indicators of compromise provided.