logo

IronHusky updates the forgotten MysterySnail RAT to target Russia and Mongolia

ID: d28b98da-5f35-5bb6-a0b1-4deed3c1b9d8

STIX ID: report--d28b98da-5f35-5bb6-a0b1-4deed3c1b9d8

Feed Name: Securelist by Kaspersky

Threat Score
80/100

Date Published: 2025-04-17

Date Updated: 2026-04-29

Author: GReAT

...
...

Kaspersky GReAT documents the reappearance and active use of the MysterySnail RAT (and a single‑module variant dubbed MysteryMonoSnail) in targeted intrusions against Mongolian and Russian government organizations. The report details an infection chain using a malicious MMC script that downloads a ZIP containing a legitimate Cisco executable and malicious DLLs (DLL sideloading), an intermediary backdoor that abuses the open-source piping-server for C2, modular payloads loaded reflectively (RC4/XOR encrypted attach.dat), supported commands and runtime modules, and observed C2 domains; it emphasizes that older, previously reported malware families can persist and reemerge and provides IoC access via Kaspersky threat intelligence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.