Netskope Threat Labs

Snappybee

ATP Sandbox Adv. Heuristics

Snappybee is a backdoor used by China-nexus threat actors, appearing in intrusions attributed to clusters including Earth Estries, Salt Typhoon, and UAT-8302, frequently alongside tooling such as ShadowPad, Cobalt Strike, and PoisonPlug. Its repeated appearance across unrelated named clusters shows how widely the family circulates among Chinese speaking espionage crews.

First seen
November 2022
Last seen
October 2026
Alert Name
Win32.Backdoor.Snappybee
Win32.Trojan.Snappybee
Win64.Trojan.Snappybee