SNOWYAMBER
SNOWYAMBERSNOWYAMBER
Description
A tool first used in October 2022, abusing the Notion service to communicate and download further malicious files. Two versions of this tool have been observed.
SNOWYAMBER is a dropper that was used in an espionage campaign significantly overlapping with publicly described activity linked to the APT29 and NOBELIUM activity sets. SNOWYAMBER abuses the NOTION collaboration service as a communication channel. It does not contain any other capabilities aside from downloading and executing 2nd stage. To bypass security products, SNOWYAMBER uses several antidetection and obfuscation techniques, including string encryption, dynamic API resolving, EDR/AV unhooking, and direct syscalls.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.