Skip to content

Malware

3snake

3snake can be used to read and extract memory from sshd and sudo system calls which utilize password based authentication.

3snake is a Linux malware family.

Background

This tool harvests credentials by reading memory associated with sshd and sudo system calls that rely on password-based authentication. Rather than modifying the memory of the traced process, 3snake launches a separate process for each command, pulling out strings tied to password-based authentication.


Source: Malpedia (Fraunhofer FKIE).