Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

SnappyClient

81
Global rank
50 infographic chevron month
Month rank
74 infographic chevron week
Week rank
0
IOCs

SnappyClient is a sophisticated C++-based command-and-control (C2) implant first identified in December 2025. Delivered primarily via the modular HijackLoader, it functions as a versatile remote access tool with strong information-stealing capabilities, particularly focused on cryptocurrency wallets, browser data, and system control. It employs advanced evasion techniques, encrypted communications, and modular configurations to maintain persistence and evade detection.

RAT
Type
Unknown
Origin
1 December, 2025
First seen
6 September, 2026
Last seen

How to analyze SnappyClient with ANY.RUN

RAT
Type
Unknown
Origin
1 December, 2025
First seen
6 September, 2026
Last seen

IOCs

IP addresses
48.209.138.189
23.207.210.132
23.11.41.157
2.16.241.205
2.23.246.101
48.192.1.65
138.124.250.215
2.16.241.9
178.16.52.217
88.221.169.152
48.209.133.15
74.178.240.51
204.79.197.203
23.52.181.141
184.86.251.14
40.126.31.69
172.211.123.248
135.232.92.137
2.16.241.222
88.221.169.205
Hashes
e4f60d0aa6d7f3d3b6a6494b1c861b99f649c6f9ec51abaf201b20f297327c95
2a6bb3bc75e9377414701bcf5887dd4e1b59803d717c9f7ff57100c5eeba3ef7
bb0885d1f6f81f14d725c099f4cc49560d25ecb40cc9e7286710c3cb20790ef3
d0dd7c1b64cf17b187e6617e7ae33e97add284a933ce96748ca852b19522769c
076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
2cf9393fe6b578f42dc362b2f5988e1a10dbea7d1bced43ef1e2d2e11b826cb2
0702046fea7d88e48991443fc2eb8c24dd723ffe1479fb19e7efc5789988def2
4c062fe6cb6e74b08d5925625af6dd2990c1e2c8da4ba326c1466e352fc9e79b
7f9b56ef50f4b4aa1912971f4d9bc994250309749e4a01787de3c661df20ddb4
0715e681d2b292b8f0d1f00a472c1d7eb3919b7da4e49ef2d36ad3f74bf48468
7523c62abdb7628c5a9dad8f97d8d8c5c040ede36535e531a8a3748b6cae7e00
2921a11f25dadaa24aa79a548e4e81508c2e5e56af2d833d65e2bcce448ce2f5
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7
6a39f865fa268d52383d16b0aa9720d74623931943bb46b031f39112bcbf32fb
4dbfc417d053ba6867308671f1c61f4dcafc61f058d4044db532da6d3bde3615
324e2f2241604e53b88bd590213385abbb2961d3f17debfb4d40e4fa7bd9c4c0
6df5e87bfe261f38a5810313c8221c39b5b15206ce672e1a87167edcf82f43ba
1bd79cbe00331e87f4405b01d3574d24294f54730a66471b054bab2bd580e687
188b36f44885930db97f519f8d6be95e1e7cef1d665ae708c286b8295a88124d
3a1a9cbe319c41dcca237c4a71e0cc3f9e112b2557295aa97ed3a2011d07d69e
Domains
th.bing.com
google.com
www.microsoft.com
client.wns.windows.com
crl.microsoft.com
settings-win.data.microsoft.com
fe3cr.delivery.mp.microsoft.com
activation-v2.sls.microsoft.com
ocsp.digicert.com
oneocsp.microsoft.com
sunshinedreamuk.com
login.live.com
slscr.update.microsoft.com
www.bing.com
nexusrules.officeapps.live.com
go.microsoft.com
self.events.data.microsoft.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
play.google.com
static.edge.microsoftapp.net
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaagb6jmmcovb6saaaaaaay%3d
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
https://www.bing.com/web/xlsc.aspx?t=5&dl=1&f=9&wsbc=1
https://www.bing.com/manifest/threshold.appcache
https://www.bing.com/as/api/windowscortanapane/v2/init
https://www.bing.com/dsb/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=us&setlang=en-us&clientdatetime=9%2f6%2f2026%2c%2012%3a27%3a39%20pm
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=ru&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=2&cvid=a74d8ec3594841a38ea3f5aebfc9b694&ig=b30046153cb04a65a021c3299c0489f1
https://www.bing.com/rb/1d/cc,nc/8qgg5w3ncsqflirnejktkex2-pa.css?bu=ehmocpqkexmmcnmscq4kexl5uqq7cnl5&or=w
https://www.bing.com/th?id=odswg.7e681b5e-8530-4c49-9079-dbc6e6a74426&pid=dsb
https://www.bing.com/rb/1d/cc,nc/dkse3syhvijzh9mpm4nc3lq7l5i.css?bu=d6ojrwmxcxm8cdej1wl55wl5ef0jexm7cg&or=w
https://www.bing.com/rb/2h/jnc,nj/pgzn-64g_wyro1novemmruil668.js?bu=areekgu&or=w
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=run&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=3&cvid=a74d8ec3594841a38ea3f5aebfc9b694&ig=bc89b620b4fa429b813e94a9f8b09ed4
https://www.bing.com/rp/53deturhav5kbhy-gxbgbwghcig.br.js
https://www.bing.com/rp/54gnhw5any81inhrc24jhrw6sho.br.css
https://www.bing.com/rp/5_qy3kn7cmdiuiz_gxikyiisle0.br.js
https://www.bing.com/rp/6y5lpywr0gtwwzp2qtdq9bu5hkm.br.js
Last Seen at

Recent blog posts

post image
Release Notes: Faster TI Investigations, Fres...
watchers 4347
comments 0
post image
Triage & Response Bottlenecks Eating into...
watchers 4009
comments 0
post image
Major Cyber Attacks in August 2026: US and EU...
watchers 9877
comments 0

SnappyClient Exposed: Remote Access, Data Theft, and a Blind Spot for Defenders

Key Takeaways

  • SnappyClient is a C++-based C2 implant first identified in December 2025, delivered through the HijackLoader malware loader.
  • It combines remote access (terminal, process control, file management) with data theft (keylogging, screenshots, browser and crypto wallet credentials) in a single tool.
  • Its primary goal appears to be cryptocurrency theft, including real-time clipboard hijacking that swaps copied wallet addresses for attacker-controlled ones.
  • Heavy use of AMSI bypass, Heaven's Gate, direct system calls, and transacted hollowing makes SnappyClient difficult for signature-based and API-hooking security tools to detect.
  • Delivery has relied on social engineering — including a fake site impersonating a telecom brand and a ClickFix-based chain — rather than software exploits, making user training a critical defense layer.
  • Reverse proxy support for FTP, VNC, SOCKS5, and RLOGIN lets attackers pivot from a single infected machine into the wider network.
  • Businesses can move from reactive to proactive defense by combining ANY.RUN Threat Intelligence Lookup, for confirming whether indicators are tied to SnappyClient and related infrastructure, with Threat Intelligence Feeds, for streaming fresh malicious IPs, domains, and URLs directly into existing security tools.

domainName:"tdd.ambiltogel.net"

Domain linked to SnappyClient by ANY.RUN TI Lookup Domain linked to SnappyClient by ANY.RUN TI Lookup

What is SnappyClient Malware?

SnappyClient is a compact but feature-rich C2 framework implant written in C++. Unlike single-purpose stealers that grab one batch of credentials and disappear, SnappyClient is designed for sustained, flexible access to a compromised host. Once deployed, it pulls two encrypted configuration files from its C2 server — commonly referred to in research as an EventsDB and a SoftwareDB — which tell the implant what to watch for and what to steal.

The malware can capture full-resolution screenshots, log every keystroke, open a remote terminal, and manipulate running processes: listing, suspending, resuming, or killing them at will, and injecting its own code into legitimate processes to blend in. Its file-management module can browse, copy, move, rename, delete, compress, or extract files and folders, including password-protected archives, and it can download and execute additional payloads on demand.

SnappyClient's defining trait is its evasion toolkit. It uses AMSI bypass techniques to slip past Windows' built-in scanning interface, leverages the Heaven's Gate technique to move between 32-bit and 64-bit execution contexts, calls system functions directly rather than through hooked API calls, and uses transacted hollowing to inject code into processes without leaving the usual forensic footprint. Network communications are encrypted with ChaCha20-Poly1305 over a custom protocol, which frustrates traditional traffic inspection. Code-level overlaps with HijackLoader — shared API structures and syscall-mapping logic — suggest the two projects may share developers or infrastructure.

Delivery has so far relied on social engineering rather than exploited vulnerabilities: a fake website impersonating telecom provider Telefónica served HijackLoader to German-speaking visitors, and a separate campaign chained the ClickFix technique with the GhostPulse loader to drop HijackLoader, which in turn decrypted and loaded SnappyClient directly into memory.

View SnappyClient sample analysis in ANY.RUN Sandbox

SnappyClient attack exposed in Interactive Sandbox SnappyClient attack exposed in Interactive Sandbox

How SnappyClient Threatens Businesses and Organizations

Snappyclient poses severe risks by enabling long-term persistence and targeted data exfiltration. Attackers can steal credentials, session cookies, browser profiles, and crypto assets, leading to financial losses, account takeovers, and intellectual property theft. Remote access features allow lateral movement, network reconnaissance, and deployment of additional payloads (e.g., ransomware).

In-memory operation and evasion tactics reduce detection windows, while clipboard manipulation and wallet targeting can result in immediate cryptocurrency theft. For businesses, this translates to disrupted operations, regulatory compliance violations (e.g., data breach notifications), remediation costs, and reputational damage—especially in sectors handling sensitive financial or customer data.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most at Risk?

SnappyClient's observed lures and capabilities point to a few sectors with elevated exposure:

  • Cryptocurrency and fintech businesses — direct targeting of wallet software (MetaMask, Phantom, Coinbase Wallet, Exodus, Ledger Live, Atomic Wallet, Trezor Suite) and clipboard-based transaction hijacking make any organization handling digital assets a high-value target.
  • Telecommunications customers and telecom-adjacent brands — the impersonation of a major telecom provider suggests threat actors see telecom brand trust as an effective lure, putting telecom customers and lookalike-vulnerable brands at risk of being spoofed.
  • German-speaking markets and European enterprises — the earliest documented campaign specifically targeted German-speaking users, indicating a regional focus that could expand to other European markets.
  • Organizations with weaker endpoint monitoring of browser and process activity — because SnappyClient leans heavily on AMSI bypass, syscall evasion, and process injection, businesses without behavioral or memory-level detection are more likely to miss it.
  • Any business relying on browser-stored credentials for SaaS access — with ten browsers in scope for data theft, companies with lax credential hygiene (password reuse, unmanaged password managers) face a wider blast radius if a single machine is compromised.

The Evolution of SnappyClient and Notable Activity

SnappyClient's public history is still short, but it has already shown signs of active development and diversified delivery:

  • December 2025 — Zscaler ThreatLabz first identifies SnappyClient as a distinct malware family, delivered via HijackLoader.
  • Campaign via fake Telefónica site — a spoofed page impersonating the telecom company automatically served a HijackLoader download to German-speaking visitors; running the file triggered HijackLoader to decrypt and load SnappyClient directly into memory, avoiding disk-based detection.
  • Early February 2026 — a second delivery chain surfaces, combining the ClickFix social-engineering technique with the GhostPulse loader alongside HijackLoader, culminating in SnappyClient as the final payload. This shows the operators experimenting with multiple loader and lure combinations rather than relying on a single delivery method.
  • Ongoing — researchers note code-level similarities between SnappyClient and HijackLoader itself, suggesting continued collaboration or shared tooling between the two projects, which could mean further joint evolution of both the loader and the implant.

How SnappyClient Gets Into Systems and Spreads

SnappyClient does not rely on exploiting software vulnerabilities. Instead, it depends on convincing a user to run a file:

  • Fake or lookalike websites — a spoofed site impersonating a trusted brand (observed: a fake Telefónica page) prompts visitors to download what looks like a legitimate file or update.
  • HijackLoader as the delivery mechanism — once downloaded and executed, HijackLoader decrypts its payload and loads SnappyClient directly into memory, minimizing artifacts written to disk.
  • ClickFix-style social engineering — a documented alternate chain used the ClickFix technique, which tricks users into manually running attacker-supplied commands (often framed as a "fix" for a fake error), leading to GhostPulse and HijackLoader delivering SnappyClient as the final stage.
  • In-memory execution and process injection — after loading, SnappyClient uses transacted hollowing and direct system calls to embed itself in legitimate processes, reducing the chance of detection by tools that rely on API hooking.

There is no confirmed self-propagation (worm-like spreading) mechanism; every documented infection begins with a user interacting with a malicious site or file.

How SnappyClient Malware Functions

Once running on a host, SnappyClient operates as follows:

  • Configuration retrieval — the implant contacts its C2 server and downloads two encrypted files: an EventsDB, which defines trigger conditions (such as taking a screenshot when clipboard content matches a cryptocurrency wallet address pattern or when a window title references a crypto platform), and a SoftwareDB, which lists the specific applications and browsers to target for data theft.
  • Secure C2 channel — communications are encrypted using ChaCha20-Poly1305 with a key, nonce, and session ID exchanged at connection time, then sent as separate header and compressed-payload packets over a custom protocol.
  • Surveillance functions — continuous or triggered keylogging and screenshot capture, with EventsDB rules allowing operators to focus collection specifically around cryptocurrency activity.
  • Data theft — extraction of saved passwords, cookies, browsing history, bookmarks, session data, and extension data from at least ten browsers, plus credentials and files from other installed software and crypto wallet applications.
  • Clipboard manipulation — real-time detection and replacement of copied cryptocurrency wallet addresses to redirect transactions to attacker-controlled wallets.
  • Remote access and control — a remote terminal, process listing/suspension/termination, and file-system management (browse, copy, move, rename, delete, compress/extract, including password-protected archives).
  • Network pivoting — reverse proxy support for FTP, VNC, SOCKS5, and RLOGIN, letting attackers tunnel further access through the compromised host.
  • Evasion — AMSI bypass, Heaven's Gate for cross-mode execution, direct system calls to avoid hooked APIs, and transacted hollowing for stealthy code injection.

View the attack chain in ANY.RUN Interactive Sandbox:

SnappyClient detonated in Interactive Sandbox SnappyClient detonated in Interactive Sandbox

The analyzed sample starts execution as a 7-Zip SFX executable from the user's Desktop.

SnappyClient starts in the system SnappyClient starts in the system

After execution, it drops multiple files into the temporary directory, including required libraries and additional components.

SnappyClient files SnappyClient files

The initial executable launches WizardDa42.exe, which acts as a HijackLoader component and continues the infection chain.

HijackLoader component in the processes HijackLoader component in the processes

During execution, the loader creates several additional processes disguised as legitimate applications, including AlphVector.exe, Crisp.exe, NeuroManag.exe, and VirtualAr.exe. These files are placed in locations such as C:\ProgramData\extadvanced_arm64 and user AppData directories to blend with normal software.

SnappyClient additional files SnappyClient additional files

The sandbox detected SnappyClient activity in the VirtualAr.exe process. The malware performs system information collection, including reading the computer name, machine GUID, and checking system location settings. It also contains screenshot functionality according to YARA detection.

Malware’s activity in the system Malware’s activity in the system

Network activity shows VirtualAr.exe contacting an external server classified as suspicious C2 activity, indicating communication with the malware infrastructure.

Malware contacts a server Malware contacts a server

How Businesses Can Use ANY.RUN’s Threat Intelligence Solutions Against SnappyClient

Because SnappyClient relies on evasive loaders and in-memory execution, static file scanning alone often isn't enough — security teams need visibility into behavior, network traffic, and fast-moving indicators as they emerge.

Threat Intelligence Lookup and ANY.RUN Threat Intelligence Feeds together give teams both sides of that picture: TI Lookup lets analysts search across a growing database of sandbox-derived indicators, hashes, and behavioral patterns to confirm whether a suspicious file, domain, or C2 address is tied to SnappyClient, HijackLoader, or related campaigns, while TI Feeds streams freshly observed malicious IPs, domains, and URLs — sourced from live sandbox sessions — directly into SIEM, IDS/IPS, and EDR tools so defenses update automatically as new SnappyClient infrastructure surfaces. Used together, they help SOC teams move from reactive cleanup to catching SnappyClient's fake lure pages and C2 infrastructure before an implant ever reaches memory.

destinationIP:"45.76.42.205"

Suspicious IP linked to to SnappyClient, HijackLoader by TI Lookup Suspicious IP linked to to SnappyClient, HijackLoader by TI Lookup

Beyond threat intelligence, businesses can reduce SnappyClient risk with:

  • Browser and credential hygiene — enforcing managed password managers instead of browser-saved passwords, and requiring MFA on all SaaS and VPN access so stolen credentials alone aren't enough.
  • Behavioral and memory-based endpoint detection — since SnappyClient bypasses AMSI and hides via process injection, EDR tuned to detect Heaven's Gate transitions, unusual syscall patterns, and transacted hollowing offers better odds than signature-based tools alone.
  • Clipboard and crypto-transaction verification — training finance and crypto-handling staff to manually verify wallet addresses before confirming transactions, rather than trusting a pasted value.
  • User awareness against ClickFix-style lures — since one delivery path relies on tricking users into manually pasting and running commands, staff training should specifically cover this technique, not just generic phishing.
  • Egress and DNS monitoring — watching for connections to newly registered or suspicious domains and unusual outbound proxy traffic (FTP/VNC/SOCKS5/RLOGIN) that could indicate SnappyClient's reverse-proxy activity.
  • Interactive sandbox analysis — detonating suspicious downloads or ClickFix-style prompts in an interactive sandbox before they reach production endpoints, to catch in-memory loaders like HijackLoader before they execute on a real machine.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

SnappyClient shows how far financially motivated malware has moved beyond simple credential stealers. By combining long-term remote access, targeted cryptocurrency theft, and a deep evasion toolkit in one compact implant, it gives attackers both the immediate payoff of drained wallets and the durable foothold needed for repeated exploitation. For businesses, the lesson is that defenses tuned only to known signatures or single-stage phishing won't be enough — visibility into behavior, network infrastructure, and fresh threat intelligence is what closes the gap SnappyClient is built to exploit.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

SnappyClient Malware FAQ

1. What is SnappyClient?

SnappyClient is a C++ C2 implant delivered via HijackLoader. It combines remote access (terminal, process control, file management) with data theft (keylogging, screenshots, credentials, crypto wallet hijacking).

2. How is SnappyClient delivered to targets?

It relies entirely on social engineering—primarily spoofed brand websites (e.g., fake Telefónica sites) and ClickFix-style lures—rather than software exploits.

3. Why is SnappyClient difficult for standard security tools to detect?

It operates in-memory and heavily utilizes advanced evasion techniques: AMSI bypass, Heaven's Gate, direct system calls (bypassing API hooks), transacted hollowing, and ChaCha20-Poly1305 encrypted traffic.

4. What are its primary financial and operational threats?

Its main goal is cryptocurrency theft via real-time clipboard address swapping and targeting wallet software. It also enables long-term persistence, reverse proxying (SOCKS5, VNC, etc.) for lateral movement, and deployment of additional payloads.

5. Who is most at risk from SnappyClient campaigns?

  • Fintech and crypto-handling organizations.
  • Telecom customers (due to spoofed brand lures).
  • Organizations in European markets (initially targeting German speakers).
  • Companies relying heavily on browser-stored credentials and lacking behavioral EDR.

6. How can a SOC build defenses against SnappyClient?

To counter its evasion capabilities, a SOC should implement:

  • Behavioral & Memory Monitoring: EDR tuned for Heaven’s Gate, direct syscalls, and transacted hollowing (since API hooks/signatures fail).
  • Credential & Session Protection: Enforce enterprise password managers and mandatory MFA instead of storing credentials in browsers.
  • Egress & DNS Rules: Block/monitor custom proxy protocols (VNC, SOCKS5, RLOGIN) and newly registered domains.
  • User Training: Specifically target ClickFix lures and instruct staff to manually verify copied crypto wallet addresses.

7. How do ANY.RUN solutions help SOC teams counter SnappyClient?

SOC and MSSP teams can integrate ANY.RUN's solutions across the entire incident response lifecycle to build a solid system for early detection of SnappyClient:

  • Monitoring & Prevention: Threat Intelligence Feeds automatically stream fresh SnappyClient C2 IPs, domains, and URLs directly into SIEM/EDR/IDS perimeter defenses, blocking active delivery campaigns before payloads ever reach endpoints.
  • Triage & Response: When suspicious files or ClickFix prompts bypass initial controls, analysts detonate them in the Interactive Sandbox to safely trigger evasive loaders (like HijackLoader) and expose in-memory behavior, C2 traffic, and payloads in real time. Analysts can also use Threat Intelligence Lookup to query extracted hashes, network artifacts, and behavioral patterns against a global threat database, instantly confirming links to SnappyClient infrastructure and scoping the incident.
  • Threat Hunting: TI Lookup helps security teams extract additional indicators and behavioral patterns and feed them into local SIEM/EDR rules to hunt across the environment for hidden persistence, proxy activity, or lateral movement.

HAVE A LOOK AT

FlowerStorm screenshot
FlowerStorm
flowerstorm
FlowerStorm is a phishing-as-a-service (PhaaS) platform used by cybercriminals to steal Microsoft 365 credentials and bypass multi-factor authentication (MFA) protections through adversary-in-the-middle (AiTM) attacks. Emerging after the disruption of Rockstar2FA in late 2024, FlowerStorm rapidly gained popularity among attackers targeting enterprises across North America and Europe.
Read More
Phishing kit screenshot
Phishing kit
tycoon evilproxy sneaky2fa
Phishing kits are pre-packaged sets of malicious tools designed to make it easy for cybercriminals to launch phishing attacks. These kits replicate legitimate websites, steal credentials, and often include backend infrastructure for managing stolen data.
Read More
Pay2Key screenshot
Pay2Key is a ransomware strain primarily written in C++ for Windows (with recent Linux variants), attributed to Iranian-linked actors, notably the Fox Kitten APT group (also known as UNC757 or related operations). First observed in late 2020, it employs double-extortion tactics (encrypting files and threatening to leak stolen data) while showing signs of both financial and state-aligned motivations. It has resurfaced in campaigns targeting Western organizations, including rapid encryption attacks on healthcare.
Read More
Xeno RAT screenshot
Xeno RAT
xenorat
Xeno RAT is an open-source malware mainly distributed through drive-by downloads. The core capabilities of this threat include remote control, keystroke logging, webcam and microphone access. Equipped with advanced utilities, such as Hidden Virtual Network Computing and Socks5 reverse proxy, Xeno RAT is most frequently used in attacks against individual users.
Read More
ValleyRAT screenshot
ValleyRAT
valleyrat
ValleyRAT is a classic remote access trojan first documented in 2023, targeting mainly Windows systems. It is used by threat actors to gain persistent access to infected devices, steal data, and control compromised machines. ValleyRAT is notable for its relatively advanced evasion techniques and its connections to a prominent Chinese APT group.
Read More
RedLine screenshot
RedLine
redline stealer redline stealer malware
RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.
Read More