Phantom in the Machine: Inside Salt Typhoon’s “SnappyBee” Backdoor
ID: 1d2b055c-873e-529c-ae70-319d1e62d694
STIX ID: report--1d2b055c-873e-529c-ae70-319d1e62d694
Feed Name: securityonline.info
### Executive summary Darktrace's analysis dissects SnappyBee (Deed RAT), a modular backdoor linked to Salt Typhoon, highlighting its post-compromise persistence and stealth techniques — including custom packing, DLL side-loading, dynamic API resolution, in-memory ARC4 decryption (mbedtls), and hooking of legitimate executables — and warns that it is used to deploy additional tools such as Cobalt Strike and the Demodex rootkit, underscoring the need for manual unpacking, dynamic debugging, and behavior-based detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
