Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

SnappyClient

79
Global rank
77 infographic chevron month
Month rank
78 infographic chevron week
Week rank

SnappyClient is a sophisticated C++-based command-and-control (C2) implant first identified in December 2025. Delivered primarily via the modular HijackLoader, it functions as a versatile remote access tool with strong information-stealing capabilities, particularly focused on cryptocurrency wallets, browser data, and system control. It employs advanced evasion techniques, encrypted communications, and modular configurations to maintain persistence and evade detection.

RAT
Type
Unknown
Origin
1 December, 2025
First seen
25 September, 2026
Last seen

How to analyze SnappyClient with ANY.RUN

RAT
Type
Unknown
Origin
1 December, 2025
First seen
25 September, 2026
Last seen

IOCs

IP addresses
172.67.140.49
150.171.109.99
142.251.110.101
142.251.13.113
150.171.109.105
172.211.123.250
2.17.251.76
142.250.154.102
150.171.28.11
23.214.22.232
23.37.194.81
23.37.193.247
150.171.27.11
135.232.92.97
142.251.127.84
131.253.33.203
142.251.20.95
48.209.138.168
52.123.243.83
48.209.138.189
Hashes
34f6f27c26d1bb8682ebb42ae401f558228fd608455bd7c6561d5fd500b7d05b
814e619eab543efecd46ad68fc8b3570faae3d2477a7a00c30ea91f9ed47099a
86387ca0fcb8187c2aacc4cf627e71090e2fa2feefaa6acc2dd3c2107c673e0a
ebce096d5060e7d8a33683263057841c50555ef3c98df8e3a48e0f534d976f39
ba0284f9316bccad25053a24ae9482de8d17da592be6233f6729e612906c63df
f55ee86cf653b2ed5ca8fa0ebd54d7b6faf7e6e5ff2db63b46d9ecc8f7774dcf
65cb11d090b32e0fb3c740a736c13c0a47cb1bcb265c084e3de5bb7474fb662f
6f9aaba073e70d0dc106b27c6006b95ea6ef47e19caa28608d83a310d416ff2d
6e506590a119f932b51eb549e78c6d0fab1b412a5cca8c320e328813acdc20ac
8888d0c0e2463178844312e69dbfd7e76ff4874add65ad325e1eb535dc2cd630
2e45c08e1c77698f26c1fe71a2d02dabc118deaa119d7f80ac77ac228a82bbeb
3333cf1fb2b0c15ea819787ba672d2274f3136e6a8729f2e5d2796b740688183
ea4d8d8fd1de22885dc300dde896fcad6ab0eefb240622299dff5f2e8fceb27f
36cc32bb8c339989756bac5826852fb8f80d541aab35d8899686b15bb06efb1e
96ee955686d67eb5a79db5deeabf3efce9f7e9f28c2af270ce2f210d9ebe0e99
4042effb4a5dd5c4cc72af11dc7fcba6ce12c60a1d5dcda8396d22103de489e8
981f2179c8a71dedd53048d09b6c4d7b6d5ba30441f3132b381cc70dbb9bbfc9
b3a8b93f05a3ebbe2942d92101bf1ccb48df804606f3edae48dd46df35082b7d
fa809c459129ad31e8093decf1e037ef8b5c92e4069d09eba675f183becd8b16
9e9b51adecb9fd13dc876a269ddc5f52110d8597dee8c39979e28bb4c5dcab58
Domains
client.wns.windows.com
fe3cr.delivery.mp.microsoft.com
settings-win.data.microsoft.com
icons.duckduckgo.com
strategyvote.com
crl.microsoft.com
edge.microsoft.com
go.microsoft.com
ocsp.digicert.com
www.gstatic.com
login.live.com
update.googleapis.com
clientservices.googleapis.com
optimizationguide-pa.googleapis.com
config.edge.skype.com
slscr.update.microsoft.com
safebrowsing.googleapis.com
intercdn.shop
www.google.com
api.edgeoffer.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:djzr_4ukipdw5gbq6yt5k8e9q6agqo0hmw7759dorme&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://login.live.com/ppsecure/deviceaddcredential.srf
https://strategyvote.com/
https://copilot.microsoft.com/c/api/user/eligibility
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://strategyvote.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
https://icons.duckduckgo.com/ip3/strategy.com.ico
https://strategyvote.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/d76008a69eab/main.js?
https://xpaywalletcdn.azureedge.net/mswallet/expresscheckout/v1/getglobalconfig?edgechannel=stable&edgeversion=133.0.3065.92&configversion=0
https://strategyvote.com/cdn-cgi/challenge-platform/h/b/jsd/oneshot/d76008a69eab/0.12255022760217915:1790298028:noz9bkw2glhu8m8x6c5j681rrucbe4daeksetu3fnuy/a4064bb7a8f794ed
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d280%2526e%253d1
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
Last Seen at

Recent blog posts

post image
ANY.RUN at RootedCON Valencia 2026: Where Cyb...
watchers 769
comments 0
post image
Phishing Risk Across 5 Key US Industries: ANY...
watchers 5619
comments 0
post image
CSuite Targets US and EU Organizations with D...
watchers 11500
comments 0

SnappyClient Exposed: Remote Access, Data Theft, and a Blind Spot for Defenders

Key Takeaways

  • SnappyClient is a C++-based C2 implant first identified in December 2025, delivered through the HijackLoader malware loader.
  • It combines remote access (terminal, process control, file management) with data theft (keylogging, screenshots, browser and crypto wallet credentials) in a single tool.
  • Its primary goal appears to be cryptocurrency theft, including real-time clipboard hijacking that swaps copied wallet addresses for attacker-controlled ones.
  • Heavy use of AMSI bypass, Heaven's Gate, direct system calls, and transacted hollowing makes SnappyClient difficult for signature-based and API-hooking security tools to detect.
  • Delivery has relied on social engineering — including a fake site impersonating a telecom brand and a ClickFix-based chain — rather than software exploits, making user training a critical defense layer.
  • Reverse proxy support for FTP, VNC, SOCKS5, and RLOGIN lets attackers pivot from a single infected machine into the wider network.
  • Businesses can move from reactive to proactive defense by combining ANY.RUN Threat Intelligence Lookup, for confirming whether indicators are tied to SnappyClient and related infrastructure, with Threat Intelligence Feeds, for streaming fresh malicious IPs, domains, and URLs directly into existing security tools.

domainName:"tdd.ambiltogel.net"

Domain linked to SnappyClient by ANY.RUN TI Lookup Domain linked to SnappyClient by ANY.RUN TI Lookup

What is SnappyClient Malware?

SnappyClient is a compact but feature-rich C2 framework implant written in C++. Unlike single-purpose stealers that grab one batch of credentials and disappear, SnappyClient is designed for sustained, flexible access to a compromised host. Once deployed, it pulls two encrypted configuration files from its C2 server — commonly referred to in research as an EventsDB and a SoftwareDB — which tell the implant what to watch for and what to steal.

The malware can capture full-resolution screenshots, log every keystroke, open a remote terminal, and manipulate running processes: listing, suspending, resuming, or killing them at will, and injecting its own code into legitimate processes to blend in. Its file-management module can browse, copy, move, rename, delete, compress, or extract files and folders, including password-protected archives, and it can download and execute additional payloads on demand.

SnappyClient's defining trait is its evasion toolkit. It uses AMSI bypass techniques to slip past Windows' built-in scanning interface, leverages the Heaven's Gate technique to move between 32-bit and 64-bit execution contexts, calls system functions directly rather than through hooked API calls, and uses transacted hollowing to inject code into processes without leaving the usual forensic footprint. Network communications are encrypted with ChaCha20-Poly1305 over a custom protocol, which frustrates traditional traffic inspection. Code-level overlaps with HijackLoader — shared API structures and syscall-mapping logic — suggest the two projects may share developers or infrastructure.

Delivery has so far relied on social engineering rather than exploited vulnerabilities: a fake website impersonating telecom provider Telefónica served HijackLoader to German-speaking visitors, and a separate campaign chained the ClickFix technique with the GhostPulse loader to drop HijackLoader, which in turn decrypted and loaded SnappyClient directly into memory.

View SnappyClient sample analysis in ANY.RUN Sandbox

SnappyClient attack exposed in Interactive Sandbox SnappyClient attack exposed in Interactive Sandbox

How SnappyClient Threatens Businesses and Organizations

Snappyclient poses severe risks by enabling long-term persistence and targeted data exfiltration. Attackers can steal credentials, session cookies, browser profiles, and crypto assets, leading to financial losses, account takeovers, and intellectual property theft. Remote access features allow lateral movement, network reconnaissance, and deployment of additional payloads (e.g., ransomware).

In-memory operation and evasion tactics reduce detection windows, while clipboard manipulation and wallet targeting can result in immediate cryptocurrency theft. For businesses, this translates to disrupted operations, regulatory compliance violations (e.g., data breach notifications), remediation costs, and reputational damage—especially in sectors handling sensitive financial or customer data.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most at Risk?

SnappyClient's observed lures and capabilities point to a few sectors with elevated exposure:

  • Cryptocurrency and fintech businesses — direct targeting of wallet software (MetaMask, Phantom, Coinbase Wallet, Exodus, Ledger Live, Atomic Wallet, Trezor Suite) and clipboard-based transaction hijacking make any organization handling digital assets a high-value target.
  • Telecommunications customers and telecom-adjacent brands — the impersonation of a major telecom provider suggests threat actors see telecom brand trust as an effective lure, putting telecom customers and lookalike-vulnerable brands at risk of being spoofed.
  • German-speaking markets and European enterprises — the earliest documented campaign specifically targeted German-speaking users, indicating a regional focus that could expand to other European markets.
  • Organizations with weaker endpoint monitoring of browser and process activity — because SnappyClient leans heavily on AMSI bypass, syscall evasion, and process injection, businesses without behavioral or memory-level detection are more likely to miss it.
  • Any business relying on browser-stored credentials for SaaS access — with ten browsers in scope for data theft, companies with lax credential hygiene (password reuse, unmanaged password managers) face a wider blast radius if a single machine is compromised.

The Evolution of SnappyClient and Notable Activity

SnappyClient's public history is still short, but it has already shown signs of active development and diversified delivery:

  • December 2025 — Zscaler ThreatLabz first identifies SnappyClient as a distinct malware family, delivered via HijackLoader.
  • Campaign via fake Telefónica site — a spoofed page impersonating the telecom company automatically served a HijackLoader download to German-speaking visitors; running the file triggered HijackLoader to decrypt and load SnappyClient directly into memory, avoiding disk-based detection.
  • Early February 2026 — a second delivery chain surfaces, combining the ClickFix social-engineering technique with the GhostPulse loader alongside HijackLoader, culminating in SnappyClient as the final payload. This shows the operators experimenting with multiple loader and lure combinations rather than relying on a single delivery method.
  • Ongoing — researchers note code-level similarities between SnappyClient and HijackLoader itself, suggesting continued collaboration or shared tooling between the two projects, which could mean further joint evolution of both the loader and the implant.

How SnappyClient Gets Into Systems and Spreads

SnappyClient does not rely on exploiting software vulnerabilities. Instead, it depends on convincing a user to run a file:

  • Fake or lookalike websites — a spoofed site impersonating a trusted brand (observed: a fake Telefónica page) prompts visitors to download what looks like a legitimate file or update.
  • HijackLoader as the delivery mechanism — once downloaded and executed, HijackLoader decrypts its payload and loads SnappyClient directly into memory, minimizing artifacts written to disk.
  • ClickFix-style social engineering — a documented alternate chain used the ClickFix technique, which tricks users into manually running attacker-supplied commands (often framed as a "fix" for a fake error), leading to GhostPulse and HijackLoader delivering SnappyClient as the final stage.
  • In-memory execution and process injection — after loading, SnappyClient uses transacted hollowing and direct system calls to embed itself in legitimate processes, reducing the chance of detection by tools that rely on API hooking.

There is no confirmed self-propagation (worm-like spreading) mechanism; every documented infection begins with a user interacting with a malicious site or file.

How SnappyClient Malware Functions

Once running on a host, SnappyClient operates as follows:

  • Configuration retrieval — the implant contacts its C2 server and downloads two encrypted files: an EventsDB, which defines trigger conditions (such as taking a screenshot when clipboard content matches a cryptocurrency wallet address pattern or when a window title references a crypto platform), and a SoftwareDB, which lists the specific applications and browsers to target for data theft.
  • Secure C2 channel — communications are encrypted using ChaCha20-Poly1305 with a key, nonce, and session ID exchanged at connection time, then sent as separate header and compressed-payload packets over a custom protocol.
  • Surveillance functions — continuous or triggered keylogging and screenshot capture, with EventsDB rules allowing operators to focus collection specifically around cryptocurrency activity.
  • Data theft — extraction of saved passwords, cookies, browsing history, bookmarks, session data, and extension data from at least ten browsers, plus credentials and files from other installed software and crypto wallet applications.
  • Clipboard manipulation — real-time detection and replacement of copied cryptocurrency wallet addresses to redirect transactions to attacker-controlled wallets.
  • Remote access and control — a remote terminal, process listing/suspension/termination, and file-system management (browse, copy, move, rename, delete, compress/extract, including password-protected archives).
  • Network pivoting — reverse proxy support for FTP, VNC, SOCKS5, and RLOGIN, letting attackers tunnel further access through the compromised host.
  • Evasion — AMSI bypass, Heaven's Gate for cross-mode execution, direct system calls to avoid hooked APIs, and transacted hollowing for stealthy code injection.

View the attack chain in ANY.RUN Interactive Sandbox:

SnappyClient detonated in Interactive Sandbox SnappyClient detonated in Interactive Sandbox

The analyzed sample starts execution as a 7-Zip SFX executable from the user's Desktop.

SnappyClient starts in the system SnappyClient starts in the system

After execution, it drops multiple files into the temporary directory, including required libraries and additional components.

SnappyClient files SnappyClient files

The initial executable launches WizardDa42.exe, which acts as a HijackLoader component and continues the infection chain.

HijackLoader component in the processes HijackLoader component in the processes

During execution, the loader creates several additional processes disguised as legitimate applications, including AlphVector.exe, Crisp.exe, NeuroManag.exe, and VirtualAr.exe. These files are placed in locations such as C:\ProgramData\extadvanced_arm64 and user AppData directories to blend with normal software.

SnappyClient additional files SnappyClient additional files

The sandbox detected SnappyClient activity in the VirtualAr.exe process. The malware performs system information collection, including reading the computer name, machine GUID, and checking system location settings. It also contains screenshot functionality according to YARA detection.

Malware’s activity in the system Malware’s activity in the system

Network activity shows VirtualAr.exe contacting an external server classified as suspicious C2 activity, indicating communication with the malware infrastructure.

Malware contacts a server Malware contacts a server

How Businesses Can Use ANY.RUN’s Threat Intelligence Solutions Against SnappyClient

Because SnappyClient relies on evasive loaders and in-memory execution, static file scanning alone often isn't enough — security teams need visibility into behavior, network traffic, and fast-moving indicators as they emerge.

Threat Intelligence Lookup and ANY.RUN Threat Intelligence Feeds together give teams both sides of that picture: TI Lookup lets analysts search across a growing database of sandbox-derived indicators, hashes, and behavioral patterns to confirm whether a suspicious file, domain, or C2 address is tied to SnappyClient, HijackLoader, or related campaigns, while TI Feeds streams freshly observed malicious IPs, domains, and URLs — sourced from live sandbox sessions — directly into SIEM, IDS/IPS, and EDR tools so defenses update automatically as new SnappyClient infrastructure surfaces. Used together, they help SOC teams move from reactive cleanup to catching SnappyClient's fake lure pages and C2 infrastructure before an implant ever reaches memory.

destinationIP:"45.76.42.205"

Suspicious IP linked to to SnappyClient, HijackLoader by TI Lookup Suspicious IP linked to to SnappyClient, HijackLoader by TI Lookup

Beyond threat intelligence, businesses can reduce SnappyClient risk with:

  • Browser and credential hygiene — enforcing managed password managers instead of browser-saved passwords, and requiring MFA on all SaaS and VPN access so stolen credentials alone aren't enough.
  • Behavioral and memory-based endpoint detection — since SnappyClient bypasses AMSI and hides via process injection, EDR tuned to detect Heaven's Gate transitions, unusual syscall patterns, and transacted hollowing offers better odds than signature-based tools alone.
  • Clipboard and crypto-transaction verification — training finance and crypto-handling staff to manually verify wallet addresses before confirming transactions, rather than trusting a pasted value.
  • User awareness against ClickFix-style lures — since one delivery path relies on tricking users into manually pasting and running commands, staff training should specifically cover this technique, not just generic phishing.
  • Egress and DNS monitoring — watching for connections to newly registered or suspicious domains and unusual outbound proxy traffic (FTP/VNC/SOCKS5/RLOGIN) that could indicate SnappyClient's reverse-proxy activity.
  • Interactive sandbox analysis — detonating suspicious downloads or ClickFix-style prompts in an interactive sandbox before they reach production endpoints, to catch in-memory loaders like HijackLoader before they execute on a real machine.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

SnappyClient shows how far financially motivated malware has moved beyond simple credential stealers. By combining long-term remote access, targeted cryptocurrency theft, and a deep evasion toolkit in one compact implant, it gives attackers both the immediate payoff of drained wallets and the durable foothold needed for repeated exploitation. For businesses, the lesson is that defenses tuned only to known signatures or single-stage phishing won't be enough — visibility into behavior, network infrastructure, and fresh threat intelligence is what closes the gap SnappyClient is built to exploit.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

SnappyClient Malware FAQ

1. What is SnappyClient?

SnappyClient is a C++ C2 implant delivered via HijackLoader. It combines remote access (terminal, process control, file management) with data theft (keylogging, screenshots, credentials, crypto wallet hijacking).

2. How is SnappyClient delivered to targets?

It relies entirely on social engineering—primarily spoofed brand websites (e.g., fake Telefónica sites) and ClickFix-style lures—rather than software exploits.

3. Why is SnappyClient difficult for standard security tools to detect?

It operates in-memory and heavily utilizes advanced evasion techniques: AMSI bypass, Heaven's Gate, direct system calls (bypassing API hooks), transacted hollowing, and ChaCha20-Poly1305 encrypted traffic.

4. What are its primary financial and operational threats?

Its main goal is cryptocurrency theft via real-time clipboard address swapping and targeting wallet software. It also enables long-term persistence, reverse proxying (SOCKS5, VNC, etc.) for lateral movement, and deployment of additional payloads.

5. Who is most at risk from SnappyClient campaigns?

  • Fintech and crypto-handling organizations.
  • Telecom customers (due to spoofed brand lures).
  • Organizations in European markets (initially targeting German speakers).
  • Companies relying heavily on browser-stored credentials and lacking behavioral EDR.

6. How can a SOC build defenses against SnappyClient?

To counter its evasion capabilities, a SOC should implement:

  • Behavioral & Memory Monitoring: EDR tuned for Heaven’s Gate, direct syscalls, and transacted hollowing (since API hooks/signatures fail).
  • Credential & Session Protection: Enforce enterprise password managers and mandatory MFA instead of storing credentials in browsers.
  • Egress & DNS Rules: Block/monitor custom proxy protocols (VNC, SOCKS5, RLOGIN) and newly registered domains.
  • User Training: Specifically target ClickFix lures and instruct staff to manually verify copied crypto wallet addresses.

7. How do ANY.RUN solutions help SOC teams counter SnappyClient?

SOC and MSSP teams can integrate ANY.RUN's solutions across the entire incident response lifecycle to build a solid system for early detection of SnappyClient:

  • Monitoring & Prevention: Threat Intelligence Feeds automatically stream fresh SnappyClient C2 IPs, domains, and URLs directly into SIEM/EDR/IDS perimeter defenses, blocking active delivery campaigns before payloads ever reach endpoints.
  • Triage & Response: When suspicious files or ClickFix prompts bypass initial controls, analysts detonate them in the Interactive Sandbox to safely trigger evasive loaders (like HijackLoader) and expose in-memory behavior, C2 traffic, and payloads in real time. Analysts can also use Threat Intelligence Lookup to query extracted hashes, network artifacts, and behavioral patterns against a global threat database, instantly confirming links to SnappyClient infrastructure and scoping the incident.
  • Threat Hunting: TI Lookup helps security teams extract additional indicators and behavioral patterns and feed them into local SIEM/EDR rules to hunt across the environment for hidden persistence, proxy activity, or lateral movement.

HAVE A LOOK AT

BTMOB RAT screenshot
BTMOB RAT
btmob
BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.
Read More
Fog Ransomware screenshot
Fog is a ransomware strain that locks and steals sensitive information both on Windows and Linux endpoints. The medial ransom demand is $220,000. The medial payment is $100,000. First spotted in the spring of 2024, it was used to attack educational organizations in the USA, later expanding on other sectors and countries. Main distribution method — compromised VPN credentials.
Read More
Sneaky 2FA screenshot
Sneaky 2FA
sneaky2fa
Sneaky 2FA is an Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts. Distributed as a Phishing-as-a-Service (PhaaS) through a Telegram bot, this malware bypasses two-factor authentication (2FA) to steal credentials and session cookies, posing a significant threat to individuals and organizations.
Read More
Remus Stealer screenshot
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
Read More
MetaStealer screenshot
MetaStealer
metastealer
MetaStealer is an info-stealing malware primarily targeting sensitive data like login credentials, payment details, and browser history. It typically infects systems via phishing emails or malicious downloads and can exfiltrate data to a command and control (C2) server. MetaStealer is known for its stealthy techniques, including evasion and persistence mechanisms, which make it difficult to detect. This malware has been actively used in various cyberattacks, particularly for financial theft and credential harvesting from individuals and organizations.
Read More
PhantomEnigma screenshot
PhantomEnigma
phantomenigma
PhantomEnigma (also known as Operation Phantom Enigma) is a sophisticated crimeware operation primarily targeting banking organizations and the public sector in Brazil. The campaign is characterized by its strategic abuse of compromised legitimate infrastructure, specifically Brazilian government (.gov.br) portals and municipal websites, to host and distribute malicious payloads.
Read More