Skip to main content
Skip to main content
3 entries found.
Updated on May 20, 2025

Trojan:Win64/SnailResin!rfn is a heuristic detection for a trojan loader attributed to the threat actor Smoke Sandstorm. Its prime purpose is to deliver the SlugResin trojan and ultimately allow unauthorized access to impacted and compromised devices. Actions undertaken post exploitation can further infringe upon sensitive information like credentials theft, privilege escalation, lateral movement within networks, and potentially deliver other payloads like ransomware, or spyware. In addition, devices compromised with this trojan will have no recovery options and can only be restored through full reformat and restoring from backup.   

Alert level: severe
Updated on Feb 14, 2024

Trojan:Win64/SnailResin.A!dha is a heuristic detection for a trojan loader attributed to the threat actor Smoke Sandstorm. Its prime purpose is to deliver the SlugResin trojan and ultimately allow unauthorized access to impacted and compromised devices. Actions undertaken post exploitation can further infringe upon sensitive information like credentials theft, privilege escalation, lateral movement within networks, and potentially deliver other payloads like ransomware, or spyware. In addition, devices compromised with this trojan will have no recovery options and can only be restored through full reformat and restoring from backup. 

Alert level: severe
Updated on Feb 14, 2024

Trojan:Win64/SnailResin.B!dha is a heuristic detection for a trojan loader attributed to the threat actor Smoke Sandstorm. Its prime purpose is to deliver the SlugResin trojan and ultimately allow unauthorized access to impacted and compromised devices. Actions undertaken post exploitation can further infringe upon sensitive information like credentials theft, privilege escalation, lateral movement within networks, and potentially deliver other payloads like ransomware, or spyware. In addition, devices compromised with this trojan will have no recovery options and can only be restored through full reformat and restoring from backup. 

Alert level: severe