Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

SnappyClient

81
Global rank
52 infographic chevron month
Month rank
80 infographic chevron week
Week rank
0
IOCs

SnappyClient is a sophisticated C++-based command-and-control (C2) implant first identified in December 2025. Delivered primarily via the modular HijackLoader, it functions as a versatile remote access tool with strong information-stealing capabilities, particularly focused on cryptocurrency wallets, browser data, and system control. It employs advanced evasion techniques, encrypted communications, and modular configurations to maintain persistence and evade detection.

RAT
Type
Unknown
Origin
1 December, 2025
First seen
4 September, 2026
Last seen

How to analyze SnappyClient with ANY.RUN

RAT
Type
Unknown
Origin
1 December, 2025
First seen
4 September, 2026
Last seen

IOCs

IP addresses
23.52.181.141
142.250.154.132
52.123.243.66
23.53.42.121
150.171.109.105
150.171.27.11
160.20.109.96
135.233.95.135
2.16.204.143
172.211.123.250
74.178.240.61
150.171.109.104
142.251.110.94
20.190.160.4
48.209.6.48
192.178.183.101
57.153.246.3
23.59.18.102
150.171.109.193
40.126.31.67
Hashes
44071e0fcffb9a9a32e8fa7010bb18dbc41afd0b176f81bf700b15b638a88a51
696e930706b5d391eb8778f73b0627ffc2be7f6c9a3e7659170d9d37fc4a97b5
bd3219d3188ae064bcba31fabd1f6a4801c1cfce0b5b44f26560cdb0becf58e4
8232c450f967d7f2f22c54582f0667f4c033ae62e6d450ff8a35c47486249443
0cf098dfe5bbb46fc0132b3cf0c54b06b4d2c8390d847ee2a65d20f9b7480f4c
9b32c491d0bfebdca1455f73c3c6f71796d433a39818c06c353da588de650f81
2824cf97513dc3ecc261f378bfd595ae95a5997e9d1c63f5731a58b1f8cd54f9
f51a7acfffec56d6751561966d947d3fd199b74528c07dabdcf5fcb33d5b2e85
64e01bc292ba2ea1699576fcc445367047520ee895e290ccee20c24c9336d8ef
7852fce59c67ddf1d6b8b997eaa1adfac004a9f3a91c37295de9223674011fba
5820d0bf9cfc363ff929492b1eb6df430039f4ac0e212a5b5411f7c2614f79d0
2445cad863be47bb1c15b57a4960b7b0d01864e63cdfde6395f3b2689dc1444b
ff702ca753a7e3b75f9d9850cc9343e28e8d60f8005a2c955c8ac2105532b2c9
af889c1deb6f9248961c2f8ba4307a8206d7163616a5b7455d17cead00068317
728d8cbd71263680a4e41399db65b3f2b8175d50ca630afd30643ced9ffe831f
22bc37b47ce8a832f39701641dc358357676e9be187a93a4c5d4b016e29238ae
cc3e9077fcc9bd0dfc5dd3924c6c48b8345f32cee24fccc508c279f45b2abe61
14895bf43ce9b76c0ff4f9aef93dbe8bb6ca496894870cf0c007b189e0cef00e
7ccc7b17bfe01c3c7dd33eff8f80d0b57fc9b175815e766c9c1c1e893725e20f
6c69ce0fe6fab14f1990a320d704fee362c175c00eb6c9224aa6f41108918ca6
Domains
msedge.b.tlu.dl.delivery.mp.microsoft.com
go.microsoft.com
play.google.com
static.edge.microsoftapp.net
self.events.data.microsoft.com
api.edgeoffer.microsoft.com
config.edge.skype.com
crl.microsoft.com
xpaywalletcdn.azureedge.net
edge.microsoft.com
oneocsp.microsoft.com
edge-cloud-resource-static.azureedge.net
www.gstatic.com
edge-mobile-static.azureedge.net
copilot.microsoft.com
www.google.com
th.bing.com
activation-v2.sls.microsoft.com
edge-consumer-static.azureedge.net
fonts.gstatic.com
URLs
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:jwou7dvjgkrvun9zquwn-szrlstijx15y21bewlzl8w&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://google.com/
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://www.google.com/
https://www.google.com/xjs/_/ss/k=xjs.hd.cyyniffa3kc.l.b1.o/am=aaaeaaagaaaaaaaaaaaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacaaaaabaaaagfaagaaaaaaabacaeaaaaaagaaaaaaaa4qaaaiabaaaaaaaaaaaaaaaaaaaacaaacqaaaaaaaaaeeabaaaaaaabeaaaaacaabeabaaaeaaaaaaaaaaaqaaaaaaaaaejaaaaaaaaaaaaaaabiaaaaaaaaaaaabaydbaaaacayaaaaaaaaaaaaaaaaaaaaaaaaaabeapaaaagaaaaaaaiaaaaaaeiaiqqbgaafelagaaaaaabgaqaaaaaaoffgqagaaaaaacaaaaaaagbbiaqqaaaagaaaacaaiaagaccaaaajkaaaeg0iaaaqcaaaaaaeaaaaaaabaaaaaaaaaaaaraaaaaaaaaaaajaaabggbaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqae/d=1/ed=1/br=1/rs=act90oeuhcqev6ripe297goepuw9qbgasa/m=cdos,hsm,jsa,mb4zub,cet90b,snun3,qddgke,stsdmc,dtl0hd,ehdfl,yv5bee,d,csi?cb=121509378
https://www.google.com/xjs/_/js/k=xjs.hd.de.3dn_xwg87ts.2019.o/am=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaibbaaaaaqcaaaaaaaaaaaaaaagabaaaaaaaaaaaaaaaaaaaaaacagcbaacqaaaaaaaaaeeabaaaaeaaaeaaawacaabeabaaawaaaaaaaaaaaaaaaaaaaaaajeaaaaeaiaaad-wqaraaaaaaaaaabiaaadaaaaaaaawaaaabaeaaaaiaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaeaaiaaaaaafaaaaaiaaaaaaaaaaaaaaaaaaaaaaaaaaaagaaaaaaaaaaaaaaaaagaaafaaaiaaacaaaaaaaaaaaaaaaaaaadaaaaaaaaaaaaaaaaaabaaaaaaaabaaaacabcaaaaaaaaaaabaaqaaaaga6awammksgaaaaaaaaaaaaaaaaaaaaaaaaaaiaacmaxukeabaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqk8baaaaaabgmq/d=1/ed=1/dg=4/br=1/rs=act90ofpt2uhxoklo-lf81u7_otl0ybczw/ee=alejib:b8glwd;afeap:tkrajf;bmxagc:e5bfse;bgs6mb:fidj5d;bjwmce:cxx2wb;bujtu:v6yjn;ciztgb:kqhykb;cxxawb:yyrlvc;dqeued:fevhcf;dulqb:rkfg5c;dkk6ge:jzmw9e;dpcr3d:zl72xf;eabsz:mxzt9d;esrpqc:mntjvc;evnhjf:pw70gc;ejxhpb:pshqh;emz2bf:zr1jrb;enlcnd:wehg4;f54iae:zgsfh;f9mqte:uorcbe;fsxmue:fizr8b;fkukfc:i8h2c;fmv9nc:o1tzwc;g0khtb:liaoz;glezl:j1a7od;hmddwe:g8qudb;htpxrd:gx8jab;ibadcc:ryqurb;ioglcf:b5lhvb;isdwvc:qzxzob;jxjsm:ii1rgf;jxs8fb:qj0suc;jqsq7d:y9ephe;jsbnhc:xd8iud;k08hxe:zmbglf;k5nytd:zdzcre;ka3p2:c3jnce;kdb6nb:fe9n2;koxck:ozqgte;kqzwid:zmkkn;kdihef:bwtnj;kpraue:tia57b;lbgrlc:sdcwhb,xvmnvd;lbn8cf:bj9l0c;leikze:byftob,lsjvmc;lxa8b:q7odkd;lsnahb:ucglnb;mnkade:kmcd1d;nj1rfe:qtnobf;npkak:sdcwhb;nseox:lazg7b;njiwef:yvgi7d;np8qkd:dpx6qc;nyt6ic:jn2sgd;oifwub:qfoycd;ogagbe:cnte0;oiqe2c:tfpek;ook5v:sp69o;oohiye:mpeaqb;pjplud:poes9b;pptlxd:pjyjx;q1ow7b:x5csu;q7ij9c:bvlz3d;qe20be:gilto;qfoglf:pq2aoe;qgr0gd:mlhmy;qylf2b:paqyud;qw8feb:jpavue;r4iiib:qwfekf;r9ulx:cr7ufe;rcf5sd:x1kbmd;raf5me:mgvfmc;sltqo:kh1xye;smdl4c:ftfgo;snun3:zwdk9d,xd8kp;snk4je:wwmhg;sci3yc:e7hzgb,e7hzgb;shpf6e:n0pvgc;snahre:mgctob;swcqad:fxbczc;szqq3e:dnhofb;tiuvqd:lwtjwd;troz1d:vvvzjb;u96prd:fsr04;ubkjz:lgdjgb;udry1c:n0f29d,w50nvd,eps46d,wciyue;uvmjed:eesrsb;uvzb9c:ivpz6d;uyrieb:hztaqc;uyg7kb:wqd0g;v2htte:rolty;vgrfx:vfqbr;vmuem:pl7sbc;vn6jic:ddqyuf;vocgde:yquhtb;vha7bd:vamqff;vsaqsb:pgf2re;w9qsqe:yncwwc;wdgyfe:jcvoxd;wxtneb:qu9bmd;wfmdue:g3mjlb;wl55ib:vgbikb;y3c5sd:fgbfle;yizmrd:a1yn5d;yv5bee:ivpz6d;ynhubf:snssob;zsh6tc:qavyle;zweua:afr4cf;zloomb:p0i0ec;a56pne:jefcwb;aaje9c:whw6ef;acj9tf:qkftvc;avzq3e:emevib;az61od:artwj;aci7y:z5tr6c;buikwb:wmwehe;bcpxsc:gszljb;cet90b:ws9tlc;cftwae:gt8qnd;diosbb:zggg9b;dllj2:qqt3gf;dxdzv:a7qtqd;dowigb:ebz3mb,ebz3mb;dtl0hd:llqwfe;ebaesb:ck63tb;ebz5nd:audvde;ehdfl:ofjvkb;ejkchc:atg1be;eo3lse:uefomb;euoxy:ozjbq;g8nkx:u4mzkc;gaub4:tn6bme;gbfhr:qztzib;gtvsi:ekuoyd;h3myod:ws9tlc;hk67qb:qweo5b;hvic1b:kqhykb;hehb1:sfczq;hjro6e:f62sg;hlqgx:fwz1ic;hslsyc:vl118;hwovhd:zw4u8c;ifqykf:qihfr;jjj2g:kf2o2b;k1o0rf:pnould;k2qxcb:xy51pe;kbam9d:mkhygd;loo0vd:ota3ae;lbfkyf:mqgdud;liaz7d:kf2o2b;mmvogb:qdm7k;mwzs9c:fz5ukf;mtkmcc:zg5tfe;nbznze:cverjb;ne6ojf:fi4rsc;nebwnb:mxkx9d;njw4gd:dpfzh;nrdcw:sueode;ogtauc:soxfj;osunyd:ftfgo,ftfgo;oulnpc:ragdlc;oibhre:oumkrd;okuaud:witadb;pkjixd:vcenhc;pnsl2d:j9yuyc;pxdryb:jkokve;pj82le:ww04df;qgv2uc:hhi04c;qqeooc:kum7z,d7ysfd;qzx2fc:j0xre;qas3gd:yilg6e;qafbpd:sgy6zb;qavrxe:i0c9u;qddgke:d7ysfd,x4fyxe;rdexkf:fekkd;rmwaj:pms6sd;ropkz:hjoqoe;stsdmc:jksfdf;szmdvc:rdgefc;th4iie:ymry6;tesrsb:bmlai;toskvd:zcqp3;trzl0b:qy8pfe;ujfyce:wj5gbc;uuqky:u2v3ud;veycnb:faqsvd;vrlmvf:iw9xo;vfvwpd:lcrkwe;w3bzcb:zpgaib;w9w86d:xwhueb,dt4g2b,gkd90c,lwvzve;wfpbg:jbgbbc;wqlyve:alufp;wr5frb:o1gjze,ttcote;wv5pjc:l8kgxe;x9n9ie:kh4qof;xbbsrc:new1qc;xparob:avqz9b;yil5ab:mt0zbd;ysnimc:cpibjd;yxtchf:kum7z;z97ygf:oug9te;zaigpb:sl0pxd/m=cdos,hsm,jsa,mb4zub,cet90b,snun3,qddgke,stsdmc,dtl0hd,ehdfl,yv5bee,d,csi?cb=121509378
https://www.google.com/async/hpba?yv=3&cs=0&ei=ey2aapmic_sxxc8p08n5wau&async=_basejs:/xjs/_/js/k%3dxjs.hd.de.3dn_xwg87ts.2019.o/am%3daaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaibbaaaaaqcaaaaaaaaaaaaaaagabaaaaaaaaaaaaaaaaaaaaaacagabaacqaaaaaaaaaeeabaaaaeaaaeaaawacaabeaaaaawaaaaaaaaaaaaaaaaaaaaaajeaaaaeaiaaad-wqaraaaaaaaaaabiaaadaaaaaaaawaaaabaeaaaaiaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaeaaiaaaaaafaaaaaiaaaaaaaaaaaaaaaaaaaaaaaaaaaagaaaaaaaaaaaaaaaaagaaafaaaiaaacaaaaaaaaaaaaaaaaaaadaaaaaaaaaaaaaaaaaabaaaaaaaabaaaacabcaaaaaaaaaaabaaqaaaaga6awammksgaaaaaaaaaaaaaaaaaaaaaaaaaaiaacmaxukaabaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqk8baaaaaabgmq/dg%3d0/br%3d1/rs%3dact90ohk2tlzhopy18jgsvvl2djgdyaigq?cb%3d121509378,_basecss:/xjs/_/ss/k%3dxjs.hd.cyyniffa3kc.l.b1.o/am%3daaaeaaagaaaaaaaaaaaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacaaaaabaaaagfaagaaaaaaabacaeaaaaaagaaaaaaaa4qaaaiabaaaaaaaaaaaaaaaaaaaacaaacqaaaaaaaaaeeabaaaaaaabeaaaaacaabeabaaaeaaaaaaaaaaaqaaaaaaaaaejaaaaaaaaaaaaaaabiaaaaaaaaaaaabaydbaaaacayaaaaaaaaaaaaaaaaaaaaaaaaaabeapaaaagaaaaaaaiaaaaaaeiaiqqbgaafelagaaaaaabgaqaaaaaaoffgqagaaaaaacaaaaaaagbbiaqqaaaagaaaacaaiaagaccaaaajkaaaeg0iaaaqcaaaaaaeaaaaaaabaaaaaaaaaaaaraaaaaaaaaaaajaaabggbaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqae/br%3d1/rs%3dact90oeuhcqev6ripe297goepuw9qbgasa?cb%3d121509378,_basecomb:/xjs/_/js/k%3dxjs.hd.de.3dn_xwg87ts.2019.o/ck%3dxjs.hd.cyyniffa3kc.l.b1.o/am%3daaaeaaagaaaaaaaaaaaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacaaaaabaaaagfaagaaibbaabacqgaaaaaagaaaaaaaa4qbaaiabaaaaaaaaaaaaaaaaacagcbaacqaaaaaaaaaeeabaaaaeaabeaaawacaabeabaaa0aaaaaaaaaaaqaaaaaaaaaejeaaaaeaiaaad-wqbraaaaaaaaaabibaydbaaaacaywaaaabaeaaaaiaaeaaaaaaaaaabeapaaaagaaaaaaaiaaaaaaeiaiqqbgaafelagaiaaaabgaqaaaaaaoffgqagaaaaaacgaaaaaagbbiaqqaaaagaaafcaaiaagcccaaaajkaaaeg0iaaaqdaaaaaaeaaaaaaabaaabaaaaaaaaraaaacabcaaaajaaabggbaaqaaaaga6awammksgaaaaaaaaaaaaaaaaaaaaaaaaaaiaacmaxukeabaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqk8baaaaaabgmq/d%3d1/ed%3d1/dg%3d0/br%3d1/ujg%3d1/rs%3dact90ogdsizrzkvb6rk3ug5qsnbrle8nqq?cb%3d121509378,_fmt:prog,_id:_ey2aapmic_sxxc8p08n5wau_16&sp_imghp=false&sp_hpep=2&sp_hpte=0&vet=10ahukewjzqnnjznswaxx0s_edhdnkhlgqj-0kccq..i
https://www.google.com/gen_204?atyp=i&ct=bxjs&cad=&b=0&ei=ey2aapmic_sxxc8p08n5wau&zx=1788513657378&opi=89978449
https://www.google.com/gen_204?ei=ey2aapmic_sxxc8p08n5wau&vet=10ahukewjzqnnjznswaxx0s_edhdnkhlgqhjahcdc..s&bl=jqv9&s=webhp&gl=de&pc=search_homepage&ismobile=false
https://www.google.com/gen_204?s=webhp&t=aft&atyp=csi&ei=ey2aapmic_sxxc8p08n5wau&rt=wsrt.459,hst.40,prt.235,aft.235&folr=_ey2aapmic_sxxc8p08n5wau_16&imn=8&dtc=196&stc=40&ima=0&imad=0&imac=2&wh=650&nt=navigate&dt=&ts=87803&nhp=h2&ant=replace&opi=89978449
https://www.google.com/gen_204?s=async&astyp=hpba&t=all&atyp=csi&ei=ey2aauejgsqgxc8psteqsaw&rt=ipf.9,ipfr.125,ttfb.125,st.125,ipfrl.126,acrt.126,aaft.126,art.126,ns.-581&twt=1&mwt=1&imn=0&ima=0&sv=&cb=112&ucb=102&folid=_ey2aapmic_sxxc8p08n5wau_16
https://www.google.com/gen_204?atyp=csi&ei=ey2aapmic_sxxc8p08n5wau&s=webhp&t=all&folr=_ey2aapmic_sxxc8p08n5wau_16&imn=8&dtc=196&stc=40&ima=0&imad=0&imac=2&wh=650&nt=navigate&dt=&ts=87803&nhp=h2&ant=replace&tbdba=67&tbdaa=0&thdba=0&thdaa=0&ime=1&imeh=0&imeha=0&imehb=0&imea=0&imeb=0&imel=0&imed=0&imeeb=0&imexb=0&scp=0&cb=87503&ucb=287049&lts=87803&adh=&mem=ujhs.10,tjhs.18,jhsl.2248,dm.4&nv=ne.1,feid.83f2d784-ecee-4837-a44e-7f4ee2ffc8de&net=dl.3650,ect.4g,rtt.50,sd.0&hp=&p=bs.true&rt=hst.40,prt.235,aft.235,xjses.291,xjsee.345,xjs.345,wsrt.459,cst.0,dnst.0,rqst.147,rspt.37,sslt.0,rqstt.349,unt.292,cstt.348,dit.743&zx=1788513657581&opi=89978449
https://www.google.com/gen_204?atyp=i&ct=psnt&cad=&nt=navigate&ei=ey2aapmic_sxxc8p08n5wau&zx=1788513657586&opi=89978449
https://www.google.com/xjs/_/js/k=xjs.hd.de.3dn_xwg87ts.2019.o/ck=xjs.hd.cyyniffa3kc.l.b1.o/am=aaaeaaagaaaaaaaaaaaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacaaaaabaaaagfaagaaibbaabacqgaaaaaagaaaaaaaa4qbaaiabaaaaaaaaaaaaaaaaacagcbaacqaaaaaaaaaeeabaaaaeaabeaaawacaabeabaaa0aaaaaaaaaaaqaaaaaaaaaejeaaaaeaiaaad-wqbraaaaaaaaaabibaydbaaaacaywaaaabaeaaaaiaaeaaaaaaaaaabeapaaaagaaaaaaaiaaaaaaeiaiqqbgaafelagaiaaaabgaqaaaaaaoffgqagaaaaaacgaaaaaagbbiaqqaaaagaaafcaaiaagcccaaaajkaaaeg0iaaaqdaaaaaaeaaaaaaabaaabaaaaaaaaraaaacabcaaaajaaabggbaaqaaaaga6awammksgaaaaaaaaaaaaaaaaaaaaaaaaaaiaacmaxukeabaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqk8baaaaaabgmq/d=0/dg=0/br=1/ujg=1/rs=act90ogdsizrzkvb6rk3ug5qsnbrle8nqq/m=sy10m,hgv0mf,sy24h,zmpthf,ueshwc,sy24f,sy19g,yhnubc,sy2eu,sy2er,vtmfj,sy2bq,sysm,sy2bp,sy2bo,n8yo7e,sy2bt,sy1wo,sy1wp,sy1iy,sy1iz,sy1j3,sy1hy,sy1hx,sy1is,sy1i9,sy1ia,sy1i7,sy1i5,sy1i4,sy1fk,sy1i8,sy1g7,sy11p,sy1it,sy1il,sy1ih,sy1dg,sy1i2,sy1fq,sy1dj,sy1di,sy9e,sy1dh,sy1df,sy1dd,sych,syh7,sy1ig,sy1ie,sy1if,sy1i1,sy1id,sy1i3,sy1ii,sy1i0,sy1ic,syo1,syl6,syl9,syl7,sy2bs,jywekf,u9eyge,sy14y,lol8vb,sy151,sy150,sy143,sy142,sy13d,sy137,sy13e,sy13y,syds,sydt,sydm,sy141,sy13b,sy139,sy138,syhj,sy136,sy13x,sy13v,sy13u,sy13t,syir,syhk,syhi,syec,sy13w,sy13z,sy13c,sy13i,sy12z,sy140,sy13k,sy13p,sy13l,sy13h,sy13g,sy13f,sy131,sy12w,sy11r,sy11q,sy132,ms4mzb,sy10d,b2qlpe,sy197,nzu6v,sy19p,sy9n,wlnqgd,sy12v,sy12t,sy12s,dpree,sy19r,sy19q,nabpbb,abd,sy4ev,tdfkye?cb=121509378&xjs=s3
https://www.google.com/xjs/_/js/md=2/k=xjs.hd.de.3dn_xwg87ts.2019.o/am=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaibbaaaaaqcaaaaaaaaaaaaaaagabaaaaaaaaaaaaaaaaaaaaaacagcbaacqaaaaaaaaaeeabaaaaeaaaeaaawacaabeabaaawaaaaaaaaaaaaaaaaaaaaaajeaaaaeaiaaad-wqaraaaaaaaaaabiaaadaaaaaaaawaaaabaeaaaaiaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaeaaiaaaaaafaaaaaiaaaaaaaaaaaaaaaaaaaaaaaaaaaagaaaaaaaaaaaaaaaaagaaafaaaiaaacaaaaaaaaaaaaaaaaaaadaaaaaaaaaaaaaaaaaabaaaaaaaabaaaacabcaaaaaaaaaaabaaqaaaaga6awammksgaaaaaaaaaaaaaaaaaaaaaaaaaaiaacmaxukeabaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqk8baaaaaabgmq/rs=act90ofpt2uhxoklo-lf81u7_otl0ybczw?cb=121509378
https://www.google.com/client_204?atyp=i&biw=1352&bih=650&dpr=1&ei=ey2aapmic_sxxc8p08n5wau&opi=89978449
https://www.google.com/xjs/_/js/k=xjs.hd.de.3dn_xwg87ts.2019.o/ck=xjs.hd.cyyniffa3kc.l.b1.o/am=aaaeaaagaaaaaaaaaaaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaacaaaaabaaaagfaagaaibbaabacqgaaaaaagaaaaaaaa4qbaaiabaaaaaaaaaaaaaaaaacagcbaacqaaaaaaaaaeeabaaaaeaabeaaawacaabeabaaa0aaaaaaaaaaaqaaaaaaaaaejeaaaaeaiaaad-wqbraaaaaaaaaabibaydbaaaacaywaaaabaeaaaaiaaeaaaaaaaaaabeapaaaagaaaaaaaiaaaaaaeiaiqqbgaafelagaiaaaabgaqaaaaaaoffgqagaaaaaacgaaaaaagbbiaqqaaaagaaafcaaiaagcccaaaajkaaaeg0iaaaqdaaaaaaeaaaaaaabaaabaaaaaaaaraaaacabcaaaajaaabggbaaqaaaaga6awammksgaaaaaaaaaaaaaaaaaaaaaaaaaaiaacmaxukeabaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaqk8baaaaaabgmq/d=0/dg=0/br=1/ujg=1/rs=act90ogdsizrzkvb6rk3ug5qsnbrle8nqq/m=sy2nd,sy1vv,ifl?cb=121509378&xjs=s3
Last Seen at

Recent blog posts

post image
Release Notes: Faster TI Investigations, Fres...
watchers 2635
comments 0
post image
Triage & Response Bottlenecks Eating into...
watchers 2716
comments 0
post image
Major Cyber Attacks in August 2026: US and EU...
watchers 7870
comments 0

SnappyClient Exposed: Remote Access, Data Theft, and a Blind Spot for Defenders

Key Takeaways

  • SnappyClient is a C++-based C2 implant first identified in December 2025, delivered through the HijackLoader malware loader.
  • It combines remote access (terminal, process control, file management) with data theft (keylogging, screenshots, browser and crypto wallet credentials) in a single tool.
  • Its primary goal appears to be cryptocurrency theft, including real-time clipboard hijacking that swaps copied wallet addresses for attacker-controlled ones.
  • Heavy use of AMSI bypass, Heaven's Gate, direct system calls, and transacted hollowing makes SnappyClient difficult for signature-based and API-hooking security tools to detect.
  • Delivery has relied on social engineering — including a fake site impersonating a telecom brand and a ClickFix-based chain — rather than software exploits, making user training a critical defense layer.
  • Reverse proxy support for FTP, VNC, SOCKS5, and RLOGIN lets attackers pivot from a single infected machine into the wider network.
  • Businesses can move from reactive to proactive defense by combining ANY.RUN Threat Intelligence Lookup, for confirming whether indicators are tied to SnappyClient and related infrastructure, with Threat Intelligence Feeds, for streaming fresh malicious IPs, domains, and URLs directly into existing security tools.

domainName:"tdd.ambiltogel.net"

Domain linked to SnappyClient by ANY.RUN TI Lookup Domain linked to SnappyClient by ANY.RUN TI Lookup

What is SnappyClient Malware?

SnappyClient is a compact but feature-rich C2 framework implant written in C++. Unlike single-purpose stealers that grab one batch of credentials and disappear, SnappyClient is designed for sustained, flexible access to a compromised host. Once deployed, it pulls two encrypted configuration files from its C2 server — commonly referred to in research as an EventsDB and a SoftwareDB — which tell the implant what to watch for and what to steal.

The malware can capture full-resolution screenshots, log every keystroke, open a remote terminal, and manipulate running processes: listing, suspending, resuming, or killing them at will, and injecting its own code into legitimate processes to blend in. Its file-management module can browse, copy, move, rename, delete, compress, or extract files and folders, including password-protected archives, and it can download and execute additional payloads on demand.

SnappyClient's defining trait is its evasion toolkit. It uses AMSI bypass techniques to slip past Windows' built-in scanning interface, leverages the Heaven's Gate technique to move between 32-bit and 64-bit execution contexts, calls system functions directly rather than through hooked API calls, and uses transacted hollowing to inject code into processes without leaving the usual forensic footprint. Network communications are encrypted with ChaCha20-Poly1305 over a custom protocol, which frustrates traditional traffic inspection. Code-level overlaps with HijackLoader — shared API structures and syscall-mapping logic — suggest the two projects may share developers or infrastructure.

Delivery has so far relied on social engineering rather than exploited vulnerabilities: a fake website impersonating telecom provider Telefónica served HijackLoader to German-speaking visitors, and a separate campaign chained the ClickFix technique with the GhostPulse loader to drop HijackLoader, which in turn decrypted and loaded SnappyClient directly into memory.

View SnappyClient sample analysis in ANY.RUN Sandbox

SnappyClient attack exposed in Interactive Sandbox SnappyClient attack exposed in Interactive Sandbox

How SnappyClient Threatens Businesses and Organizations

Snappyclient poses severe risks by enabling long-term persistence and targeted data exfiltration. Attackers can steal credentials, session cookies, browser profiles, and crypto assets, leading to financial losses, account takeovers, and intellectual property theft. Remote access features allow lateral movement, network reconnaissance, and deployment of additional payloads (e.g., ransomware).

In-memory operation and evasion tactics reduce detection windows, while clipboard manipulation and wallet targeting can result in immediate cryptocurrency theft. For businesses, this translates to disrupted operations, regulatory compliance violations (e.g., data breach notifications), remediation costs, and reputational damage—especially in sectors handling sensitive financial or customer data.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most at Risk?

SnappyClient's observed lures and capabilities point to a few sectors with elevated exposure:

  • Cryptocurrency and fintech businesses — direct targeting of wallet software (MetaMask, Phantom, Coinbase Wallet, Exodus, Ledger Live, Atomic Wallet, Trezor Suite) and clipboard-based transaction hijacking make any organization handling digital assets a high-value target.
  • Telecommunications customers and telecom-adjacent brands — the impersonation of a major telecom provider suggests threat actors see telecom brand trust as an effective lure, putting telecom customers and lookalike-vulnerable brands at risk of being spoofed.
  • German-speaking markets and European enterprises — the earliest documented campaign specifically targeted German-speaking users, indicating a regional focus that could expand to other European markets.
  • Organizations with weaker endpoint monitoring of browser and process activity — because SnappyClient leans heavily on AMSI bypass, syscall evasion, and process injection, businesses without behavioral or memory-level detection are more likely to miss it.
  • Any business relying on browser-stored credentials for SaaS access — with ten browsers in scope for data theft, companies with lax credential hygiene (password reuse, unmanaged password managers) face a wider blast radius if a single machine is compromised.

The Evolution of SnappyClient and Notable Activity

SnappyClient's public history is still short, but it has already shown signs of active development and diversified delivery:

  • December 2025 — Zscaler ThreatLabz first identifies SnappyClient as a distinct malware family, delivered via HijackLoader.
  • Campaign via fake Telefónica site — a spoofed page impersonating the telecom company automatically served a HijackLoader download to German-speaking visitors; running the file triggered HijackLoader to decrypt and load SnappyClient directly into memory, avoiding disk-based detection.
  • Early February 2026 — a second delivery chain surfaces, combining the ClickFix social-engineering technique with the GhostPulse loader alongside HijackLoader, culminating in SnappyClient as the final payload. This shows the operators experimenting with multiple loader and lure combinations rather than relying on a single delivery method.
  • Ongoing — researchers note code-level similarities between SnappyClient and HijackLoader itself, suggesting continued collaboration or shared tooling between the two projects, which could mean further joint evolution of both the loader and the implant.

How SnappyClient Gets Into Systems and Spreads

SnappyClient does not rely on exploiting software vulnerabilities. Instead, it depends on convincing a user to run a file:

  • Fake or lookalike websites — a spoofed site impersonating a trusted brand (observed: a fake Telefónica page) prompts visitors to download what looks like a legitimate file or update.
  • HijackLoader as the delivery mechanism — once downloaded and executed, HijackLoader decrypts its payload and loads SnappyClient directly into memory, minimizing artifacts written to disk.
  • ClickFix-style social engineering — a documented alternate chain used the ClickFix technique, which tricks users into manually running attacker-supplied commands (often framed as a "fix" for a fake error), leading to GhostPulse and HijackLoader delivering SnappyClient as the final stage.
  • In-memory execution and process injection — after loading, SnappyClient uses transacted hollowing and direct system calls to embed itself in legitimate processes, reducing the chance of detection by tools that rely on API hooking.

There is no confirmed self-propagation (worm-like spreading) mechanism; every documented infection begins with a user interacting with a malicious site or file.

How SnappyClient Malware Functions

Once running on a host, SnappyClient operates as follows:

  • Configuration retrieval — the implant contacts its C2 server and downloads two encrypted files: an EventsDB, which defines trigger conditions (such as taking a screenshot when clipboard content matches a cryptocurrency wallet address pattern or when a window title references a crypto platform), and a SoftwareDB, which lists the specific applications and browsers to target for data theft.
  • Secure C2 channel — communications are encrypted using ChaCha20-Poly1305 with a key, nonce, and session ID exchanged at connection time, then sent as separate header and compressed-payload packets over a custom protocol.
  • Surveillance functions — continuous or triggered keylogging and screenshot capture, with EventsDB rules allowing operators to focus collection specifically around cryptocurrency activity.
  • Data theft — extraction of saved passwords, cookies, browsing history, bookmarks, session data, and extension data from at least ten browsers, plus credentials and files from other installed software and crypto wallet applications.
  • Clipboard manipulation — real-time detection and replacement of copied cryptocurrency wallet addresses to redirect transactions to attacker-controlled wallets.
  • Remote access and control — a remote terminal, process listing/suspension/termination, and file-system management (browse, copy, move, rename, delete, compress/extract, including password-protected archives).
  • Network pivoting — reverse proxy support for FTP, VNC, SOCKS5, and RLOGIN, letting attackers tunnel further access through the compromised host.
  • Evasion — AMSI bypass, Heaven's Gate for cross-mode execution, direct system calls to avoid hooked APIs, and transacted hollowing for stealthy code injection.

View the attack chain in ANY.RUN Interactive Sandbox:

SnappyClient detonated in Interactive Sandbox SnappyClient detonated in Interactive Sandbox

The analyzed sample starts execution as a 7-Zip SFX executable from the user's Desktop.

SnappyClient starts in the system SnappyClient starts in the system

After execution, it drops multiple files into the temporary directory, including required libraries and additional components.

SnappyClient files SnappyClient files

The initial executable launches WizardDa42.exe, which acts as a HijackLoader component and continues the infection chain.

HijackLoader component in the processes HijackLoader component in the processes

During execution, the loader creates several additional processes disguised as legitimate applications, including AlphVector.exe, Crisp.exe, NeuroManag.exe, and VirtualAr.exe. These files are placed in locations such as C:\ProgramData\extadvanced_arm64 and user AppData directories to blend with normal software.

SnappyClient additional files SnappyClient additional files

The sandbox detected SnappyClient activity in the VirtualAr.exe process. The malware performs system information collection, including reading the computer name, machine GUID, and checking system location settings. It also contains screenshot functionality according to YARA detection.

Malware’s activity in the system Malware’s activity in the system

Network activity shows VirtualAr.exe contacting an external server classified as suspicious C2 activity, indicating communication with the malware infrastructure.

Malware contacts a server Malware contacts a server

How Businesses Can Use ANY.RUN’s Threat Intelligence Solutions Against SnappyClient

Because SnappyClient relies on evasive loaders and in-memory execution, static file scanning alone often isn't enough — security teams need visibility into behavior, network traffic, and fast-moving indicators as they emerge.

Threat Intelligence Lookup and ANY.RUN Threat Intelligence Feeds together give teams both sides of that picture: TI Lookup lets analysts search across a growing database of sandbox-derived indicators, hashes, and behavioral patterns to confirm whether a suspicious file, domain, or C2 address is tied to SnappyClient, HijackLoader, or related campaigns, while TI Feeds streams freshly observed malicious IPs, domains, and URLs — sourced from live sandbox sessions — directly into SIEM, IDS/IPS, and EDR tools so defenses update automatically as new SnappyClient infrastructure surfaces. Used together, they help SOC teams move from reactive cleanup to catching SnappyClient's fake lure pages and C2 infrastructure before an implant ever reaches memory.

destinationIP:"45.76.42.205"

Suspicious IP linked to to SnappyClient, HijackLoader by TI Lookup Suspicious IP linked to to SnappyClient, HijackLoader by TI Lookup

Beyond threat intelligence, businesses can reduce SnappyClient risk with:

  • Browser and credential hygiene — enforcing managed password managers instead of browser-saved passwords, and requiring MFA on all SaaS and VPN access so stolen credentials alone aren't enough.
  • Behavioral and memory-based endpoint detection — since SnappyClient bypasses AMSI and hides via process injection, EDR tuned to detect Heaven's Gate transitions, unusual syscall patterns, and transacted hollowing offers better odds than signature-based tools alone.
  • Clipboard and crypto-transaction verification — training finance and crypto-handling staff to manually verify wallet addresses before confirming transactions, rather than trusting a pasted value.
  • User awareness against ClickFix-style lures — since one delivery path relies on tricking users into manually pasting and running commands, staff training should specifically cover this technique, not just generic phishing.
  • Egress and DNS monitoring — watching for connections to newly registered or suspicious domains and unusual outbound proxy traffic (FTP/VNC/SOCKS5/RLOGIN) that could indicate SnappyClient's reverse-proxy activity.
  • Interactive sandbox analysis — detonating suspicious downloads or ClickFix-style prompts in an interactive sandbox before they reach production endpoints, to catch in-memory loaders like HijackLoader before they execute on a real machine.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

SnappyClient shows how far financially motivated malware has moved beyond simple credential stealers. By combining long-term remote access, targeted cryptocurrency theft, and a deep evasion toolkit in one compact implant, it gives attackers both the immediate payoff of drained wallets and the durable foothold needed for repeated exploitation. For businesses, the lesson is that defenses tuned only to known signatures or single-stage phishing won't be enough — visibility into behavior, network infrastructure, and fresh threat intelligence is what closes the gap SnappyClient is built to exploit.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

SnappyClient Malware FAQ

1. What is SnappyClient?

SnappyClient is a C++ C2 implant delivered via HijackLoader. It combines remote access (terminal, process control, file management) with data theft (keylogging, screenshots, credentials, crypto wallet hijacking).

2. How is SnappyClient delivered to targets?

It relies entirely on social engineering—primarily spoofed brand websites (e.g., fake Telefónica sites) and ClickFix-style lures—rather than software exploits.

3. Why is SnappyClient difficult for standard security tools to detect?

It operates in-memory and heavily utilizes advanced evasion techniques: AMSI bypass, Heaven's Gate, direct system calls (bypassing API hooks), transacted hollowing, and ChaCha20-Poly1305 encrypted traffic.

4. What are its primary financial and operational threats?

Its main goal is cryptocurrency theft via real-time clipboard address swapping and targeting wallet software. It also enables long-term persistence, reverse proxying (SOCKS5, VNC, etc.) for lateral movement, and deployment of additional payloads.

5. Who is most at risk from SnappyClient campaigns?

  • Fintech and crypto-handling organizations.
  • Telecom customers (due to spoofed brand lures).
  • Organizations in European markets (initially targeting German speakers).
  • Companies relying heavily on browser-stored credentials and lacking behavioral EDR.

6. How can a SOC build defenses against SnappyClient?

To counter its evasion capabilities, a SOC should implement:

  • Behavioral & Memory Monitoring: EDR tuned for Heaven’s Gate, direct syscalls, and transacted hollowing (since API hooks/signatures fail).
  • Credential & Session Protection: Enforce enterprise password managers and mandatory MFA instead of storing credentials in browsers.
  • Egress & DNS Rules: Block/monitor custom proxy protocols (VNC, SOCKS5, RLOGIN) and newly registered domains.
  • User Training: Specifically target ClickFix lures and instruct staff to manually verify copied crypto wallet addresses.

7. How do ANY.RUN solutions help SOC teams counter SnappyClient?

SOC and MSSP teams can integrate ANY.RUN's solutions across the entire incident response lifecycle to build a solid system for early detection of SnappyClient:

  • Monitoring & Prevention: Threat Intelligence Feeds automatically stream fresh SnappyClient C2 IPs, domains, and URLs directly into SIEM/EDR/IDS perimeter defenses, blocking active delivery campaigns before payloads ever reach endpoints.
  • Triage & Response: When suspicious files or ClickFix prompts bypass initial controls, analysts detonate them in the Interactive Sandbox to safely trigger evasive loaders (like HijackLoader) and expose in-memory behavior, C2 traffic, and payloads in real time. Analysts can also use Threat Intelligence Lookup to query extracted hashes, network artifacts, and behavioral patterns against a global threat database, instantly confirming links to SnappyClient infrastructure and scoping the incident.
  • Threat Hunting: TI Lookup helps security teams extract additional indicators and behavioral patterns and feed them into local SIEM/EDR rules to hunt across the environment for hidden persistence, proxy activity, or lateral movement.

HAVE A LOOK AT

Mispadu screenshot
Mispadu is a Windows banking trojan known for targeting online banking credentials, cryptocurrency wallets, and sensitive financial information. First identified in Latin America, the malware has continuously evolved with improved evasion techniques, phishing campaigns, and credential theft capabilities. Its reliance on social engineering rather than software vulnerabilities makes it an enduring threat to organizations whose employees interact with financial services online.
Read More
Bumblebee Loader screenshot
Bumblebee Loader
bumblebee
Bumblebee is a highly adaptable malware loader, often used by threat actors linked to the Conti and TrickBot cybercrime groups. Since its discovery in 2021, Bumblebee has been leveraged in phishing campaigns and email thread hijacking, primarily to distribute payloads like Cobalt Strike and ransomware. The malware employs obfuscation techniques, such as DLL injection and virtual environment detection, to avoid detection and sandbox analysis. Its command-and-control infrastructure and anti-analysis features allow it to persist on infected devices, where it enables further payload downloads and system compromise.
Read More
Maze screenshot
Maze
maze ransomware
Maze is ransomware — a malware type that encrypts the victim’s files and restores the data in exchange for a ransom payment. One of the most distinguishable features of Maze is that it is one of the first malware of the kind to publicly release stolen data.
Read More
Lumma screenshot
Lumma
lumma
Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.
Read More
Adware screenshot
Adware
adware
Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.
Read More
Sliver screenshot
Sliver
sliver
Sliver is an open-source command-and-control (C2) framework that has been increasingly adopted by threat actors as an alternative to tools like Cobalt Strike. Developed by security firm Bishop Fox, Sliver was initially intended for legitimate security testing and red teaming exercises. However, its robust features and open-source nature have made it attractive to malicious actors seeking to control compromised systems.
Read More