Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

SnappyClient

96
Global rank
55 infographic chevron month
Month rank
48 infographic chevron week
Week rank
0
IOCs

SnappyClient is a sophisticated C++-based command-and-control (C2) implant first identified in December 2025. Delivered primarily via the modular HijackLoader, it functions as a versatile remote access tool with strong information-stealing capabilities, particularly focused on cryptocurrency wallets, browser data, and system control. It employs advanced evasion techniques, encrypted communications, and modular configurations to maintain persistence and evade detection.

RAT
Type
Unknown
Origin
1 December, 2025
First seen
14 August, 2026
Last seen

How to analyze SnappyClient with ANY.RUN

RAT
Type
Unknown
Origin
1 December, 2025
First seen
14 August, 2026
Last seen

IOCs

IP addresses
57.153.246.3
74.178.240.61
172.217.115.4
151.101.1.91
172.211.123.250
20.190.160.67
142.251.20.139
23.52.181.141
150.171.22.17
40.126.31.1
142.251.127.84
48.209.138.189
172.67.155.17
185.93.68.46
172.217.112.4
142.250.154.101
150.171.109.194
142.250.154.100
193.169.228.147
172.66.147.243
Hashes
42b55d126d1e640b1ed7a6bdcb9a46c81df461fa7e131f4f8c7108c2c61c14de
14f92b911f9fe774720461eec5bb4761ae6bfc9445c67e30bf624a8694b4b1da
a2ca52e34b6138624ac2dd20349cde28482143b837db40a7f0fbda023077c26a
f096bc366a931fba656bdcd77b24af15a5f29fc53281a727c79f82c608ecfab8
c43668eec4a8d88a5b3a06a84f8846853fe33e54293c2db56899a5a5dfb4d944
a0c9abae18599f0a65fc654ad36251f6330794bea66b718a09d8b297f3e38e87
41c91a9c93d76295746a149dce7ebb3b9ee2cb551d84365fff108e59a61cc304
68c7ad234755b9edb06832a084d092660970c89a7305e0c47d327b6ac50dd898
a6b5ed0bc2d4e6c476a582d79f5cdcd2fb428f84b157e6befdb25c0fe359346c
225d669e47eb14d8c969799c92aaef27b66cd984872ea09284e48db46521e651
4412319ef944ebcca9581cbacb1d4e1dc614c348d1dfc5d2faaaad863d300209
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
fb077c966296d02d50ccbf7f761d2a3311a206a784a7496f331c2b0d6ad205c8
f7b24f2eb3d5eb0550527490395d2f61c3d2fe74bb9cb345197dad81b58b5fed
fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
3615498fbef408a96bf30e01c318dac2d5451b054998119080e7faac5995f590
48d535bb330519c00d150578734c6cecb056c4b5cdd2a45c70590bc896d27d9f
fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
Domains
safebrowsingohttpgateway.googleapis.com
prc.10001toto.org
www.google.com
api.edgeoffer.microsoft.com
clients2.google.com
config.edge.skype.com
slscr.update.microsoft.com
client.wns.windows.com
settings-win.data.microsoft.com
update.googleapis.com
optimizationguide-pa.googleapis.com
copilot.microsoft.com
crl.microsoft.com
example.com
edge.microsoft.com
fe3cr.delivery.mp.microsoft.com
mozilla.map.fastly.net
www.microsoft.com
login.live.com
clientservices.googleapis.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://telegram.me/m1duus
https://prc.10001toto.org/
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:f-j8qi2gr1rs4xtesfwogyvsemhcm2mjgj6rhewoqja&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://clients2.google.com/time/1/current?cup2key=8:7yf4j9id9ssg1okanzdtvmurbr3s7_quemktnsf0pwy&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1786750940&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=-3039340649090746224&agents=edgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=0&mngd=0&installdate=1786750940&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=0&lafgdate=0
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
https://copilot.microsoft.com/c/api/user/eligibility
https://go.microsoft.com/fwlink/?linkid=2133855&bucket=15
https://edge.microsoft.com/neededge/v1?bucket=15
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=-3039340649090746224&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=0&mngd=0&installdate=1786750940&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=0&lafgdate=0
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://www.bing.com/api/shopping/v1/user/shoppingsettings
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=-3039340649090746224&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=0&mngd=0&installdate=1786750940&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=0&lafgdate=0
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
Last Seen at

Recent blog posts

post image
Intelligence-Driven SOC: Modernizing Threat M...
watchers 8862
comments 0
post image
Supply Chain Security: How ANY.RUN Helps US a...
watchers 4327
comments 0
post image
Smile, You're on Camera. Part 2: Hiring Lazar...
watchers 39188
comments 0

SnappyClient Exposed: Remote Access, Data Theft, and a Blind Spot for Defenders

Key Takeaways

  • SnappyClient is a C++-based C2 implant first identified in December 2025, delivered through the HijackLoader malware loader.
  • It combines remote access (terminal, process control, file management) with data theft (keylogging, screenshots, browser and crypto wallet credentials) in a single tool.
  • Its primary goal appears to be cryptocurrency theft, including real-time clipboard hijacking that swaps copied wallet addresses for attacker-controlled ones.
  • Heavy use of AMSI bypass, Heaven's Gate, direct system calls, and transacted hollowing makes SnappyClient difficult for signature-based and API-hooking security tools to detect.
  • Delivery has relied on social engineering — including a fake site impersonating a telecom brand and a ClickFix-based chain — rather than software exploits, making user training a critical defense layer.
  • Reverse proxy support for FTP, VNC, SOCKS5, and RLOGIN lets attackers pivot from a single infected machine into the wider network.
  • Businesses can move from reactive to proactive defense by combining ANY.RUN Threat Intelligence Lookup, for confirming whether indicators are tied to SnappyClient and related infrastructure, with Threat Intelligence Feeds, for streaming fresh malicious IPs, domains, and URLs directly into existing security tools.

domainName:"tdd.ambiltogel.net"

Domain linked to SnappyClient by ANY.RUN TI Lookup Domain linked to SnappyClient by ANY.RUN TI Lookup

What is SnappyClient Malware?

SnappyClient is a compact but feature-rich C2 framework implant written in C++. Unlike single-purpose stealers that grab one batch of credentials and disappear, SnappyClient is designed for sustained, flexible access to a compromised host. Once deployed, it pulls two encrypted configuration files from its C2 server — commonly referred to in research as an EventsDB and a SoftwareDB — which tell the implant what to watch for and what to steal.

The malware can capture full-resolution screenshots, log every keystroke, open a remote terminal, and manipulate running processes: listing, suspending, resuming, or killing them at will, and injecting its own code into legitimate processes to blend in. Its file-management module can browse, copy, move, rename, delete, compress, or extract files and folders, including password-protected archives, and it can download and execute additional payloads on demand.

SnappyClient's defining trait is its evasion toolkit. It uses AMSI bypass techniques to slip past Windows' built-in scanning interface, leverages the Heaven's Gate technique to move between 32-bit and 64-bit execution contexts, calls system functions directly rather than through hooked API calls, and uses transacted hollowing to inject code into processes without leaving the usual forensic footprint. Network communications are encrypted with ChaCha20-Poly1305 over a custom protocol, which frustrates traditional traffic inspection. Code-level overlaps with HijackLoader — shared API structures and syscall-mapping logic — suggest the two projects may share developers or infrastructure.

Delivery has so far relied on social engineering rather than exploited vulnerabilities: a fake website impersonating telecom provider Telefónica served HijackLoader to German-speaking visitors, and a separate campaign chained the ClickFix technique with the GhostPulse loader to drop HijackLoader, which in turn decrypted and loaded SnappyClient directly into memory.

View SnappyClient sample analysis in ANY.RUN Sandbox

SnappyClient attack exposed in Interactive Sandbox SnappyClient attack exposed in Interactive Sandbox

How SnappyClient Threatens Businesses and Organizations

Snappyclient poses severe risks by enabling long-term persistence and targeted data exfiltration. Attackers can steal credentials, session cookies, browser profiles, and crypto assets, leading to financial losses, account takeovers, and intellectual property theft. Remote access features allow lateral movement, network reconnaissance, and deployment of additional payloads (e.g., ransomware).

In-memory operation and evasion tactics reduce detection windows, while clipboard manipulation and wallet targeting can result in immediate cryptocurrency theft. For businesses, this translates to disrupted operations, regulatory compliance violations (e.g., data breach notifications), remediation costs, and reputational damage—especially in sectors handling sensitive financial or customer data.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most at Risk?

SnappyClient's observed lures and capabilities point to a few sectors with elevated exposure:

  • Cryptocurrency and fintech businesses — direct targeting of wallet software (MetaMask, Phantom, Coinbase Wallet, Exodus, Ledger Live, Atomic Wallet, Trezor Suite) and clipboard-based transaction hijacking make any organization handling digital assets a high-value target.
  • Telecommunications customers and telecom-adjacent brands — the impersonation of a major telecom provider suggests threat actors see telecom brand trust as an effective lure, putting telecom customers and lookalike-vulnerable brands at risk of being spoofed.
  • German-speaking markets and European enterprises — the earliest documented campaign specifically targeted German-speaking users, indicating a regional focus that could expand to other European markets.
  • Organizations with weaker endpoint monitoring of browser and process activity — because SnappyClient leans heavily on AMSI bypass, syscall evasion, and process injection, businesses without behavioral or memory-level detection are more likely to miss it.
  • Any business relying on browser-stored credentials for SaaS access — with ten browsers in scope for data theft, companies with lax credential hygiene (password reuse, unmanaged password managers) face a wider blast radius if a single machine is compromised.

The Evolution of SnappyClient and Notable Activity

SnappyClient's public history is still short, but it has already shown signs of active development and diversified delivery:

  • December 2025 — Zscaler ThreatLabz first identifies SnappyClient as a distinct malware family, delivered via HijackLoader.
  • Campaign via fake Telefónica site — a spoofed page impersonating the telecom company automatically served a HijackLoader download to German-speaking visitors; running the file triggered HijackLoader to decrypt and load SnappyClient directly into memory, avoiding disk-based detection.
  • Early February 2026 — a second delivery chain surfaces, combining the ClickFix social-engineering technique with the GhostPulse loader alongside HijackLoader, culminating in SnappyClient as the final payload. This shows the operators experimenting with multiple loader and lure combinations rather than relying on a single delivery method.
  • Ongoing — researchers note code-level similarities between SnappyClient and HijackLoader itself, suggesting continued collaboration or shared tooling between the two projects, which could mean further joint evolution of both the loader and the implant.

How SnappyClient Gets Into Systems and Spreads

SnappyClient does not rely on exploiting software vulnerabilities. Instead, it depends on convincing a user to run a file:

  • Fake or lookalike websites — a spoofed site impersonating a trusted brand (observed: a fake Telefónica page) prompts visitors to download what looks like a legitimate file or update.
  • HijackLoader as the delivery mechanism — once downloaded and executed, HijackLoader decrypts its payload and loads SnappyClient directly into memory, minimizing artifacts written to disk.
  • ClickFix-style social engineering — a documented alternate chain used the ClickFix technique, which tricks users into manually running attacker-supplied commands (often framed as a "fix" for a fake error), leading to GhostPulse and HijackLoader delivering SnappyClient as the final stage.
  • In-memory execution and process injection — after loading, SnappyClient uses transacted hollowing and direct system calls to embed itself in legitimate processes, reducing the chance of detection by tools that rely on API hooking.

There is no confirmed self-propagation (worm-like spreading) mechanism; every documented infection begins with a user interacting with a malicious site or file.

How SnappyClient Malware Functions

Once running on a host, SnappyClient operates as follows:

  • Configuration retrieval — the implant contacts its C2 server and downloads two encrypted files: an EventsDB, which defines trigger conditions (such as taking a screenshot when clipboard content matches a cryptocurrency wallet address pattern or when a window title references a crypto platform), and a SoftwareDB, which lists the specific applications and browsers to target for data theft.
  • Secure C2 channel — communications are encrypted using ChaCha20-Poly1305 with a key, nonce, and session ID exchanged at connection time, then sent as separate header and compressed-payload packets over a custom protocol.
  • Surveillance functions — continuous or triggered keylogging and screenshot capture, with EventsDB rules allowing operators to focus collection specifically around cryptocurrency activity.
  • Data theft — extraction of saved passwords, cookies, browsing history, bookmarks, session data, and extension data from at least ten browsers, plus credentials and files from other installed software and crypto wallet applications.
  • Clipboard manipulation — real-time detection and replacement of copied cryptocurrency wallet addresses to redirect transactions to attacker-controlled wallets.
  • Remote access and control — a remote terminal, process listing/suspension/termination, and file-system management (browse, copy, move, rename, delete, compress/extract, including password-protected archives).
  • Network pivoting — reverse proxy support for FTP, VNC, SOCKS5, and RLOGIN, letting attackers tunnel further access through the compromised host.
  • Evasion — AMSI bypass, Heaven's Gate for cross-mode execution, direct system calls to avoid hooked APIs, and transacted hollowing for stealthy code injection.

View the attack chain in ANY.RUN Interactive Sandbox:

SnappyClient detonated in Interactive Sandbox SnappyClient detonated in Interactive Sandbox

The analyzed sample starts execution as a 7-Zip SFX executable from the user's Desktop.

SnappyClient starts in the system SnappyClient starts in the system

After execution, it drops multiple files into the temporary directory, including required libraries and additional components.

SnappyClient files SnappyClient files

The initial executable launches WizardDa42.exe, which acts as a HijackLoader component and continues the infection chain.

HijackLoader component in the processes HijackLoader component in the processes

During execution, the loader creates several additional processes disguised as legitimate applications, including AlphVector.exe, Crisp.exe, NeuroManag.exe, and VirtualAr.exe. These files are placed in locations such as C:\ProgramData\extadvanced_arm64 and user AppData directories to blend with normal software.

SnappyClient additional files SnappyClient additional files

The sandbox detected SnappyClient activity in the VirtualAr.exe process. The malware performs system information collection, including reading the computer name, machine GUID, and checking system location settings. It also contains screenshot functionality according to YARA detection.

Malware’s activity in the system Malware’s activity in the system

Network activity shows VirtualAr.exe contacting an external server classified as suspicious C2 activity, indicating communication with the malware infrastructure.

Malware contacts a server Malware contacts a server

How Businesses Can Use ANY.RUN’s Threat Intelligence Solutions Against SnappyClient

Because SnappyClient relies on evasive loaders and in-memory execution, static file scanning alone often isn't enough — security teams need visibility into behavior, network traffic, and fast-moving indicators as they emerge.

Threat Intelligence Lookup and ANY.RUN Threat Intelligence Feeds together give teams both sides of that picture: TI Lookup lets analysts search across a growing database of sandbox-derived indicators, hashes, and behavioral patterns to confirm whether a suspicious file, domain, or C2 address is tied to SnappyClient, HijackLoader, or related campaigns, while TI Feeds streams freshly observed malicious IPs, domains, and URLs — sourced from live sandbox sessions — directly into SIEM, IDS/IPS, and EDR tools so defenses update automatically as new SnappyClient infrastructure surfaces. Used together, they help SOC teams move from reactive cleanup to catching SnappyClient's fake lure pages and C2 infrastructure before an implant ever reaches memory.

destinationIP:"45.76.42.205"

Suspicious IP linked to to SnappyClient, HijackLoader by TI Lookup Suspicious IP linked to to SnappyClient, HijackLoader by TI Lookup

Beyond threat intelligence, businesses can reduce SnappyClient risk with:

  • Browser and credential hygiene — enforcing managed password managers instead of browser-saved passwords, and requiring MFA on all SaaS and VPN access so stolen credentials alone aren't enough.
  • Behavioral and memory-based endpoint detection — since SnappyClient bypasses AMSI and hides via process injection, EDR tuned to detect Heaven's Gate transitions, unusual syscall patterns, and transacted hollowing offers better odds than signature-based tools alone.
  • Clipboard and crypto-transaction verification — training finance and crypto-handling staff to manually verify wallet addresses before confirming transactions, rather than trusting a pasted value.
  • User awareness against ClickFix-style lures — since one delivery path relies on tricking users into manually pasting and running commands, staff training should specifically cover this technique, not just generic phishing.
  • Egress and DNS monitoring — watching for connections to newly registered or suspicious domains and unusual outbound proxy traffic (FTP/VNC/SOCKS5/RLOGIN) that could indicate SnappyClient's reverse-proxy activity.
  • Interactive sandbox analysis — detonating suspicious downloads or ClickFix-style prompts in an interactive sandbox before they reach production endpoints, to catch in-memory loaders like HijackLoader before they execute on a real machine.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

SnappyClient shows how far financially motivated malware has moved beyond simple credential stealers. By combining long-term remote access, targeted cryptocurrency theft, and a deep evasion toolkit in one compact implant, it gives attackers both the immediate payoff of drained wallets and the durable foothold needed for repeated exploitation. For businesses, the lesson is that defenses tuned only to known signatures or single-stage phishing won't be enough — visibility into behavior, network infrastructure, and fresh threat intelligence is what closes the gap SnappyClient is built to exploit.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

SnappyClient Malware FAQ

1. What is SnappyClient?

SnappyClient is a C++ C2 implant delivered via HijackLoader. It combines remote access (terminal, process control, file management) with data theft (keylogging, screenshots, credentials, crypto wallet hijacking).

2. How is SnappyClient delivered to targets?

It relies entirely on social engineering—primarily spoofed brand websites (e.g., fake Telefónica sites) and ClickFix-style lures—rather than software exploits.

3. Why is SnappyClient difficult for standard security tools to detect?

It operates in-memory and heavily utilizes advanced evasion techniques: AMSI bypass, Heaven's Gate, direct system calls (bypassing API hooks), transacted hollowing, and ChaCha20-Poly1305 encrypted traffic.

4. What are its primary financial and operational threats?

Its main goal is cryptocurrency theft via real-time clipboard address swapping and targeting wallet software. It also enables long-term persistence, reverse proxying (SOCKS5, VNC, etc.) for lateral movement, and deployment of additional payloads.

5. Who is most at risk from SnappyClient campaigns?

  • Fintech and crypto-handling organizations.
  • Telecom customers (due to spoofed brand lures).
  • Organizations in European markets (initially targeting German speakers).
  • Companies relying heavily on browser-stored credentials and lacking behavioral EDR.

6. How can a SOC build defenses against SnappyClient?

To counter its evasion capabilities, a SOC should implement:

  • Behavioral & Memory Monitoring: EDR tuned for Heaven’s Gate, direct syscalls, and transacted hollowing (since API hooks/signatures fail).
  • Credential & Session Protection: Enforce enterprise password managers and mandatory MFA instead of storing credentials in browsers.
  • Egress & DNS Rules: Block/monitor custom proxy protocols (VNC, SOCKS5, RLOGIN) and newly registered domains.
  • User Training: Specifically target ClickFix lures and instruct staff to manually verify copied crypto wallet addresses.

7. How do ANY.RUN solutions help SOC teams counter SnappyClient?

SOC and MSSP teams can integrate ANY.RUN's solutions across the entire incident response lifecycle to build a solid system for early detection of SnappyClient:

  • Monitoring & Prevention: Threat Intelligence Feeds automatically stream fresh SnappyClient C2 IPs, domains, and URLs directly into SIEM/EDR/IDS perimeter defenses, blocking active delivery campaigns before payloads ever reach endpoints.
  • Triage & Response: When suspicious files or ClickFix prompts bypass initial controls, analysts detonate them in the Interactive Sandbox to safely trigger evasive loaders (like HijackLoader) and expose in-memory behavior, C2 traffic, and payloads in real time. Analysts can also use Threat Intelligence Lookup to query extracted hashes, network artifacts, and behavioral patterns against a global threat database, instantly confirming links to SnappyClient infrastructure and scoping the incident.
  • Threat Hunting: TI Lookup helps security teams extract additional indicators and behavioral patterns and feed them into local SIEM/EDR rules to hunt across the environment for hidden persistence, proxy activity, or lateral movement.

HAVE A LOOK AT

DeerStealer screenshot
DeerStealer
deerstealer
DeerStealer is an information-stealing malware discovered in 2024 by ANY.RUN, primarily targeting sensitive data such as login credentials, browser history, and cryptocurrency wallet details. It is often distributed through phishing campaigns and fake Google ads that mimic legitimate platforms like Google Authenticator. Once installed, it exfiltrates the stolen data to a remote command and control (C2) server. DeerStealer’s ability to disguise itself as legitimate downloads makes it particularly dangerous for unsuspecting users.
Read More
 screenshot
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More
Akira Ransomware screenshot
Akira Ransomware emerged in March 2023 and compromised over 250 organizations by January 2024 with approximately $42 million in ransom payments. It employs double extortion tactics exfiltrating data before encryption and threatening to publish it on a dedicated website.
Read More
WannaCry screenshot
WannaCry
wannacry ransomware
WannaCry is a famous Ransomware that utilizes the EternalBlue exploit. This malware is known for infecting at least 200,000 computers worldwide and it continues to be an active and dangerous threat.
Read More
Gh0st RAT screenshot
Gh0st RAT
gh0st
Gh0st RAT is a malware with advanced trojan functionality that enables attackers to establish full control over the victim’s system. The spying capabilities of Gh0st RAT made it a go-to tool for numerous criminal groups in high-profile attacks against government and corporate organizations. The most common vector of attack involving this malware begins with spam and phishing emails.
Read More
DonutLoader screenshot
DonutLoader
donutloader donut
DonutLoader is a versatile, open-source-based in-memory loader that turns .NET assemblies, executables, DLLs, and scripts into position-independent shellcode for execution entirely in RAM. Originally derived from the popular Donut tool, it enables threat actors to bypass traditional antivirus and EDR solutions by avoiding disk writes and injecting payloads directly into legitimate Windows processes.
Read More