logo

Phantom in the Machine: Inside Salt Typhoon’s “SnappyBee” Backdoor

ID: 1d2b055c-873e-529c-ae70-319d1e62d694

STIX ID: report--1d2b055c-873e-529c-ae70-319d1e62d694

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-02-06

Date Updated: 2026-04-23

Author: Ddos

...
...

### Executive summary Darktrace's analysis dissects SnappyBee (Deed RAT), a modular backdoor linked to Salt Typhoon, highlighting its post-compromise persistence and stealth techniques — including custom packing, DLL side-loading, dynamic API resolution, in-memory ARC4 decryption (mbedtls), and hooking of legitimate executables — and warns that it is used to deploy additional tools such as Cobalt Strike and the Demodex rootkit, underscoring the need for manual unpacking, dynamic debugging, and behavior-based detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.