Description
Uroburos (a.k.a. Snake) is a sophisticated rootkit associated with the Turla threat group that targets networks for long term espionage and data exfiltration. Its kernel level design hid the implant from the operating system itself, and its peer to peer command structure let operators control fleets of infected machines invisibly. International law enforcement disrupted its infrastructure in 2024 after decades of operation, and the family remains a benchmark for state sponsored rootkit development.
Stats
- First seen
- May 2022
- Last seen
- September 2026
MITRE ATT&CK techniques
36 techniques across 7 tactics.
TA0002 Execution
TA0005 Stealth
- T1014Rootkit
- T1027Obfuscated Files or Information
- T1036Masquerading
- T1036.004Masquerade Task or Service
- T1055Process Injection
- T1055.001Dynamic-link Library Injection
- T1070Indicator Removal
- T1070.004File Deletion
- T1140Deobfuscate/Decode Files or Information
- T1205Traffic Signaling
- T1564Hide Artifacts
- T1564.005Hidden File System
- T1620Reflective Code Loading
TA0007 Discovery
TA0009 Collection
- T1005Data from Local System
TA0011 Command and Control
TA0112 Defense Impairment
- T1112Modify Registry
Associated groups
Alert name variants
| Alert Name |
|---|
| Document-HTML.Trojan.Snake |
| Generic.JS.Snake.A.0DB65353 |
| Generic.JS.Snake.A.27DADFE1 |
| Generic.JS.Snake.A.3FB9164D |
| Generic.JS.Snake.A.944EBA69 |
| Generic.JS.Snake.A.CB728D85 |
| Generic.JS.Snake.A.CD17D509 |
| GT:VB.Heur2.Snake.2.0B0771A9 |
| GT:VB.Heur2.Snake.2.11461739 |
| GT:VB.Heur2.Snake.2.21DA8654 |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-CNC Snake.Generic.Trojan traffic detected |

