Skip to content

Snap convert 1#4015

Open
RavenTait wants to merge 12 commits intodevelopfrom
snap_convert_1
Open

Snap convert 1#4015
RavenTait wants to merge 12 commits intodevelopfrom
snap_convert_1

Conversation

@RavenTait
Copy link
Copy Markdown
Contributor

First Big chunk of detections from SnapAttack

Contains 109 new detections and some new malicious powershell strings.

@nasbench
Copy link
Copy Markdown
Contributor

image

@patel-bhavin patel-bhavin added this to the v5.27.0 milestone Apr 15, 2026

PowGoop is the primary loader used by MuddyWater (also tracked as SeedWorm, Static Kitten, and MERCURY) and has been their main initial access loader since at least 2020. It abuses DLL side-loading against a fake GoogleUpdate.exe to execute a multi-stage decoding chain, a fully functional PowerShell backdoor disguised with a benign extension. The config.txt contains a hardcoded C2 address and victim GUID, beacons via modified base64-encoded HTTP, and runs C2 traffic under the legitimate Google Update process to evade network detection.

'
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we update the script to remove this extra line from the description?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants