Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 18:26:05 UTC Home > List all groups > List all tools > List all groups using tool SnifLite Tool: SnifLite Names SnifLite Category Malware Type Credential stealer Description (Group-IB) After deobfuscating the code, Group-IB found that the attacks used a sniffer from the SnifLite family, already known to Group-IB experts and used by the threat actor UltraRank. Due to the relatively small number of infected websites, the attackers most likely used the credentials in the CMS administrative panel, which, in turn, could have been compromised using malware or as a result of brute force attacks. Information Last change to this tool card: 07 January 2021 Download this tool card in JSON format All groups using tool SnifLite Changed Name Country Observed APT groups   UltraRank [Unknown] 2015-Nov 2020   1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a66b3b44-3a8f-4fba-9a0e-956abc89f879 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a66b3b44-3a8f-4fba-9a0e-956abc89f879 Page 1 of 1