Netskope Threat Labs

Uroburos

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Uroburos (a.k.a. Snake) is a sophisticated rootkit associated with the Turla threat group that targets networks for long term espionage and data exfiltration. Its kernel level design hid the implant from the operating system itself, and its peer to peer command structure let operators control fleets of infected machines invisibly. International law enforcement disrupted its infrastructure in 2024 after decades of operation, and the family remains a benchmark for state sponsored rootkit development.

First seen
May 2022
Last seen
September 2026

36 techniques across 7 tactics.

TA0002 Execution

TA0003 Persistence

TA0005 Stealth

TA0007 Discovery

  • T1012Query Registry
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery

TA0009 Collection

  • T1005Data from Local System

TA0011 Command and Control

TA0112 Defense Impairment

Alert Name
Document-HTML.Trojan.Snake
Generic.JS.Snake.A.0DB65353
Generic.JS.Snake.A.27DADFE1
Generic.JS.Snake.A.3FB9164D
Generic.JS.Snake.A.944EBA69
Generic.JS.Snake.A.CB728D85
Generic.JS.Snake.A.CD17D509
GT:VB.Heur2.Snake.2.0B0771A9
GT:VB.Heur2.Snake.2.11461739
GT:VB.Heur2.Snake.2.21DA8654