Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

SnappyClient

0
Global rank
0
Month rank
0
Week rank
0
IOCs

SnappyClient is a sophisticated C++-based command-and-control (C2) implant first identified in December 2025. Delivered primarily via the modular HijackLoader, it functions as a versatile remote access tool with strong information-stealing capabilities, particularly focused on cryptocurrency wallets, browser data, and system control. It employs advanced evasion techniques, encrypted communications, and modular configurations to maintain persistence and evade detection.

RAT
Type
Unknown
Origin
1 December, 2025
First seen
26 July, 2026
Last seen

How to analyze SnappyClient with ANY.RUN

RAT
Type
Unknown
Origin
1 December, 2025
First seen
26 July, 2026
Last seen

IOCs

Last Seen at
Last Seen at

Recent blog posts

post image
Faster Incident Response: How ANY.RUN Helps S...
watchers 5379
comments 0
post image
Kali365 Targets US Organizations with Data Th...
watchers 9149
comments 0
post image
Hidden Infrastructure Exposed: ANY.RUN Reveal...
watchers 14223
comments 0

SnappyClient Exposed: Remote Access, Data Theft, and a Blind Spot for Defenders

Key Takeaways

  • SnappyClient is a C++-based C2 implant first identified in December 2025, delivered through the HijackLoader malware loader.
  • It combines remote access (terminal, process control, file management) with data theft (keylogging, screenshots, browser and crypto wallet credentials) in a single tool.
  • Its primary goal appears to be cryptocurrency theft, including real-time clipboard hijacking that swaps copied wallet addresses for attacker-controlled ones.
  • Heavy use of AMSI bypass, Heaven's Gate, direct system calls, and transacted hollowing makes SnappyClient difficult for signature-based and API-hooking security tools to detect.
  • Delivery has relied on social engineering — including a fake site impersonating a telecom brand and a ClickFix-based chain — rather than software exploits, making user training a critical defense layer.
  • Reverse proxy support for FTP, VNC, SOCKS5, and RLOGIN lets attackers pivot from a single infected machine into the wider network.
  • Businesses can move from reactive to proactive defense by combining ANY.RUN Threat Intelligence Lookup, for confirming whether indicators are tied to SnappyClient and related infrastructure, with Threat Intelligence Feeds, for streaming fresh malicious IPs, domains, and URLs directly into existing security tools.

domainName:"tdd.ambiltogel.net"

Domain linked to SnappyClient by ANY.RUN TI Lookup Domain linked to SnappyClient by ANY.RUN TI Lookup

What is SnappyClient Malware?

SnappyClient is a compact but feature-rich C2 framework implant written in C++. Unlike single-purpose stealers that grab one batch of credentials and disappear, SnappyClient is designed for sustained, flexible access to a compromised host. Once deployed, it pulls two encrypted configuration files from its C2 server — commonly referred to in research as an EventsDB and a SoftwareDB — which tell the implant what to watch for and what to steal.

The malware can capture full-resolution screenshots, log every keystroke, open a remote terminal, and manipulate running processes: listing, suspending, resuming, or killing them at will, and injecting its own code into legitimate processes to blend in. Its file-management module can browse, copy, move, rename, delete, compress, or extract files and folders, including password-protected archives, and it can download and execute additional payloads on demand.

SnappyClient's defining trait is its evasion toolkit. It uses AMSI bypass techniques to slip past Windows' built-in scanning interface, leverages the Heaven's Gate technique to move between 32-bit and 64-bit execution contexts, calls system functions directly rather than through hooked API calls, and uses transacted hollowing to inject code into processes without leaving the usual forensic footprint. Network communications are encrypted with ChaCha20-Poly1305 over a custom protocol, which frustrates traditional traffic inspection. Code-level overlaps with HijackLoader — shared API structures and syscall-mapping logic — suggest the two projects may share developers or infrastructure.

Delivery has so far relied on social engineering rather than exploited vulnerabilities: a fake website impersonating telecom provider Telefónica served HijackLoader to German-speaking visitors, and a separate campaign chained the ClickFix technique with the GhostPulse loader to drop HijackLoader, which in turn decrypted and loaded SnappyClient directly into memory.

View SnappyClient sample analysis in ANY.RUN Sandbox

SnappyClient attack exposed in Interactive Sandbox SnappyClient attack exposed in Interactive Sandbox

How SnappyClient Threatens Businesses and Organizations

Snappyclient poses severe risks by enabling long-term persistence and targeted data exfiltration. Attackers can steal credentials, session cookies, browser profiles, and crypto assets, leading to financial losses, account takeovers, and intellectual property theft. Remote access features allow lateral movement, network reconnaissance, and deployment of additional payloads (e.g., ransomware).

In-memory operation and evasion tactics reduce detection windows, while clipboard manipulation and wallet targeting can result in immediate cryptocurrency theft. For businesses, this translates to disrupted operations, regulatory compliance violations (e.g., data breach notifications), remediation costs, and reputational damage—especially in sectors handling sensitive financial or customer data.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Who Is Most at Risk?

SnappyClient's observed lures and capabilities point to a few sectors with elevated exposure:

  • Cryptocurrency and fintech businesses — direct targeting of wallet software (MetaMask, Phantom, Coinbase Wallet, Exodus, Ledger Live, Atomic Wallet, Trezor Suite) and clipboard-based transaction hijacking make any organization handling digital assets a high-value target.
  • Telecommunications customers and telecom-adjacent brands — the impersonation of a major telecom provider suggests threat actors see telecom brand trust as an effective lure, putting telecom customers and lookalike-vulnerable brands at risk of being spoofed.
  • German-speaking markets and European enterprises — the earliest documented campaign specifically targeted German-speaking users, indicating a regional focus that could expand to other European markets.
  • Organizations with weaker endpoint monitoring of browser and process activity — because SnappyClient leans heavily on AMSI bypass, syscall evasion, and process injection, businesses without behavioral or memory-level detection are more likely to miss it.
  • Any business relying on browser-stored credentials for SaaS access — with ten browsers in scope for data theft, companies with lax credential hygiene (password reuse, unmanaged password managers) face a wider blast radius if a single machine is compromised.

The Evolution of SnappyClient and Notable Activity

SnappyClient's public history is still short, but it has already shown signs of active development and diversified delivery:

  • December 2025 — Zscaler ThreatLabz first identifies SnappyClient as a distinct malware family, delivered via HijackLoader.
  • Campaign via fake Telefónica site — a spoofed page impersonating the telecom company automatically served a HijackLoader download to German-speaking visitors; running the file triggered HijackLoader to decrypt and load SnappyClient directly into memory, avoiding disk-based detection.
  • Early February 2026 — a second delivery chain surfaces, combining the ClickFix social-engineering technique with the GhostPulse loader alongside HijackLoader, culminating in SnappyClient as the final payload. This shows the operators experimenting with multiple loader and lure combinations rather than relying on a single delivery method.
  • Ongoing — researchers note code-level similarities between SnappyClient and HijackLoader itself, suggesting continued collaboration or shared tooling between the two projects, which could mean further joint evolution of both the loader and the implant.

How SnappyClient Gets Into Systems and Spreads

SnappyClient does not rely on exploiting software vulnerabilities. Instead, it depends on convincing a user to run a file:

  • Fake or lookalike websites — a spoofed site impersonating a trusted brand (observed: a fake Telefónica page) prompts visitors to download what looks like a legitimate file or update.
  • HijackLoader as the delivery mechanism — once downloaded and executed, HijackLoader decrypts its payload and loads SnappyClient directly into memory, minimizing artifacts written to disk.
  • ClickFix-style social engineering — a documented alternate chain used the ClickFix technique, which tricks users into manually running attacker-supplied commands (often framed as a "fix" for a fake error), leading to GhostPulse and HijackLoader delivering SnappyClient as the final stage.
  • In-memory execution and process injection — after loading, SnappyClient uses transacted hollowing and direct system calls to embed itself in legitimate processes, reducing the chance of detection by tools that rely on API hooking.

There is no confirmed self-propagation (worm-like spreading) mechanism; every documented infection begins with a user interacting with a malicious site or file.

How SnappyClient Malware Functions

Once running on a host, SnappyClient operates as follows:

  • Configuration retrieval — the implant contacts its C2 server and downloads two encrypted files: an EventsDB, which defines trigger conditions (such as taking a screenshot when clipboard content matches a cryptocurrency wallet address pattern or when a window title references a crypto platform), and a SoftwareDB, which lists the specific applications and browsers to target for data theft.
  • Secure C2 channel — communications are encrypted using ChaCha20-Poly1305 with a key, nonce, and session ID exchanged at connection time, then sent as separate header and compressed-payload packets over a custom protocol.
  • Surveillance functions — continuous or triggered keylogging and screenshot capture, with EventsDB rules allowing operators to focus collection specifically around cryptocurrency activity.
  • Data theft — extraction of saved passwords, cookies, browsing history, bookmarks, session data, and extension data from at least ten browsers, plus credentials and files from other installed software and crypto wallet applications.
  • Clipboard manipulation — real-time detection and replacement of copied cryptocurrency wallet addresses to redirect transactions to attacker-controlled wallets.
  • Remote access and control — a remote terminal, process listing/suspension/termination, and file-system management (browse, copy, move, rename, delete, compress/extract, including password-protected archives).
  • Network pivoting — reverse proxy support for FTP, VNC, SOCKS5, and RLOGIN, letting attackers tunnel further access through the compromised host.
  • Evasion — AMSI bypass, Heaven's Gate for cross-mode execution, direct system calls to avoid hooked APIs, and transacted hollowing for stealthy code injection.

View the attack chain in ANY.RUN Interactive Sandbox:

SnappyClient detonated in Interactive Sandbox SnappyClient detonated in Interactive Sandbox

The analyzed sample starts execution as a 7-Zip SFX executable from the user's Desktop.

SnappyClient starts in the system SnappyClient starts in the system

After execution, it drops multiple files into the temporary directory, including required libraries and additional components.

SnappyClient files SnappyClient files

The initial executable launches WizardDa42.exe, which acts as a HijackLoader component and continues the infection chain.

HijackLoader component in the processes HijackLoader component in the processes

During execution, the loader creates several additional processes disguised as legitimate applications, including AlphVector.exe, Crisp.exe, NeuroManag.exe, and VirtualAr.exe. These files are placed in locations such as C:\ProgramData\extadvanced_arm64 and user AppData directories to blend with normal software.

SnappyClient additional files SnappyClient additional files

The sandbox detected SnappyClient activity in the VirtualAr.exe process. The malware performs system information collection, including reading the computer name, machine GUID, and checking system location settings. It also contains screenshot functionality according to YARA detection.

Malware’s activity in the system Malware’s activity in the system

Network activity shows VirtualAr.exe contacting an external server classified as suspicious C2 activity, indicating communication with the malware infrastructure.

Malware contacts a server Malware contacts a server

How Businesses Can Use ANY.RUN’s Threat Intelligence Solutions Against SnappyClient

Because SnappyClient relies on evasive loaders and in-memory execution, static file scanning alone often isn't enough — security teams need visibility into behavior, network traffic, and fast-moving indicators as they emerge.

Threat Intelligence Lookup and ANY.RUN Threat Intelligence Feeds together give teams both sides of that picture: TI Lookup lets analysts search across a growing database of sandbox-derived indicators, hashes, and behavioral patterns to confirm whether a suspicious file, domain, or C2 address is tied to SnappyClient, HijackLoader, or related campaigns, while TI Feeds streams freshly observed malicious IPs, domains, and URLs — sourced from live sandbox sessions — directly into SIEM, IDS/IPS, and EDR tools so defenses update automatically as new SnappyClient infrastructure surfaces. Used together, they help SOC teams move from reactive cleanup to catching SnappyClient's fake lure pages and C2 infrastructure before an implant ever reaches memory.

destinationIP:"45.76.42.205"

Suspicious IP linked to to SnappyClient, HijackLoader by TI Lookup Suspicious IP linked to to SnappyClient, HijackLoader by TI Lookup

Beyond threat intelligence, businesses can reduce SnappyClient risk with:

  • Browser and credential hygiene — enforcing managed password managers instead of browser-saved passwords, and requiring MFA on all SaaS and VPN access so stolen credentials alone aren't enough.
  • Behavioral and memory-based endpoint detection — since SnappyClient bypasses AMSI and hides via process injection, EDR tuned to detect Heaven's Gate transitions, unusual syscall patterns, and transacted hollowing offers better odds than signature-based tools alone.
  • Clipboard and crypto-transaction verification — training finance and crypto-handling staff to manually verify wallet addresses before confirming transactions, rather than trusting a pasted value.
  • User awareness against ClickFix-style lures — since one delivery path relies on tricking users into manually pasting and running commands, staff training should specifically cover this technique, not just generic phishing.
  • Egress and DNS monitoring — watching for connections to newly registered or suspicious domains and unusual outbound proxy traffic (FTP/VNC/SOCKS5/RLOGIN) that could indicate SnappyClient's reverse-proxy activity.
  • Interactive sandbox analysis — detonating suspicious downloads or ClickFix-style prompts in an interactive sandbox before they reach production endpoints, to catch in-memory loaders like HijackLoader before they execute on a real machine.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

SnappyClient shows how far financially motivated malware has moved beyond simple credential stealers. By combining long-term remote access, targeted cryptocurrency theft, and a deep evasion toolkit in one compact implant, it gives attackers both the immediate payoff of drained wallets and the durable foothold needed for repeated exploitation. For businesses, the lesson is that defenses tuned only to known signatures or single-stage phishing won't be enough — visibility into behavior, network infrastructure, and fresh threat intelligence is what closes the gap SnappyClient is built to exploit.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

SnappyClient Malware FAQ

1. What is SnappyClient?

SnappyClient is a C++ C2 implant delivered via HijackLoader. It combines remote access (terminal, process control, file management) with data theft (keylogging, screenshots, credentials, crypto wallet hijacking).

2. How is SnappyClient delivered to targets?

It relies entirely on social engineering—primarily spoofed brand websites (e.g., fake Telefónica sites) and ClickFix-style lures—rather than software exploits.

3. Why is SnappyClient difficult for standard security tools to detect?

It operates in-memory and heavily utilizes advanced evasion techniques: AMSI bypass, Heaven's Gate, direct system calls (bypassing API hooks), transacted hollowing, and ChaCha20-Poly1305 encrypted traffic.

4. What are its primary financial and operational threats?

Its main goal is cryptocurrency theft via real-time clipboard address swapping and targeting wallet software. It also enables long-term persistence, reverse proxying (SOCKS5, VNC, etc.) for lateral movement, and deployment of additional payloads.

5. Who is most at risk from SnappyClient campaigns?

  • Fintech and crypto-handling organizations.
  • Telecom customers (due to spoofed brand lures).
  • Organizations in European markets (initially targeting German speakers).
  • Companies relying heavily on browser-stored credentials and lacking behavioral EDR.

6. How can a SOC build defenses against SnappyClient?

To counter its evasion capabilities, a SOC should implement:

  • Behavioral & Memory Monitoring: EDR tuned for Heaven’s Gate, direct syscalls, and transacted hollowing (since API hooks/signatures fail).
  • Credential & Session Protection: Enforce enterprise password managers and mandatory MFA instead of storing credentials in browsers.
  • Egress & DNS Rules: Block/monitor custom proxy protocols (VNC, SOCKS5, RLOGIN) and newly registered domains.
  • User Training: Specifically target ClickFix lures and instruct staff to manually verify copied crypto wallet addresses.

7. How do ANY.RUN solutions help SOC teams counter SnappyClient?

SOC and MSSP teams can integrate ANY.RUN's solutions across the entire incident response lifecycle to build a solid system for early detection of SnappyClient:

  • Monitoring & Prevention: Threat Intelligence Feeds automatically stream fresh SnappyClient C2 IPs, domains, and URLs directly into SIEM/EDR/IDS perimeter defenses, blocking active delivery campaigns before payloads ever reach endpoints.
  • Triage & Response: When suspicious files or ClickFix prompts bypass initial controls, analysts detonate them in the Interactive Sandbox to safely trigger evasive loaders (like HijackLoader) and expose in-memory behavior, C2 traffic, and payloads in real time. Analysts can also use Threat Intelligence Lookup to query extracted hashes, network artifacts, and behavioral patterns against a global threat database, instantly confirming links to SnappyClient infrastructure and scoping the incident.
  • Threat Hunting: TI Lookup helps security teams extract additional indicators and behavioral patterns and feed them into local SIEM/EDR rules to hunt across the environment for hidden persistence, proxy activity, or lateral movement.

HAVE A LOOK AT

Octo screenshot
Octo
octo coper
Octo malware, also known as ExobotCompact or Coper, is a sophisticated Android banking trojan that has evolved from earlier malware family Exobot. It poses a significant threat to financial institutions, mobile users, and enterprise networks.
Read More
Arechclient2 screenshot
Arechclient2
arechclient2
The Arechclient2 malware is a sophisticated .NET-based Remote Access Trojan (RAT) that collects sensitive information, such as browser credentials, from infected computers. It employs various stealth techniques, including Base64 encoding to obscure its code and the ability to pause activities to evade automated security tools. The malware also can adjust Windows Defender settings and uses code injection to manipulate legitimate processes.
Read More
MassLogger screenshot
MassLogger
masslogger
MassLogger is a credential stealer and keylogger first identified in April 2020. It has been actively used in cyber campaigns to exfiltrate sensitive information from compromised systems. It is designed for easy use by less tech-savvy actors and is prominent for the capability of spreading via USB drives. It targets both individuals and organizations in various industries, mostly in Europe and the USA.
Read More
DoubleTrouble screenshot
DoubleTrouble
doubletrouble
DoubleTrouble is a new-generation Android malware designed to quietly infiltrate mobile devices, harvest sensitive data, hijack financial operations, and maintain long-term persistence. Unlike commodity Android trojans, it blends advanced evasion, dual-stage infection, and dynamic payload updates, making it a rising mobile threat for both consumers and organizations.
Read More
JOMANGY screenshot
JOMANGY is a PHP webshell and backdoor family targeting vulnerable FreePBX servers. It is designed to establish long-term access to compromised VoIP infrastructure, enable toll fraud, and survive remediation attempts through multiple self-reinforcing persistence mechanisms. Unlike many traditional webshells, JOMANGY employs a highly resilient architecture that can automatically restore itself even after partial removal.
Read More
DarkCloud screenshot
DarkCloud
darkcloud
DarkCloud is an infostealer that focuses on collecting and exfiltrating browser data from the infected device. The malware is also capable of keylogging and crypto address swapping. DarkCloud is typically delivered to victims’ computers via phishing emails.
Read More