Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now

WhiteSnake

115
Global rank
95 infographic chevron month
Month rank
72 infographic chevron week
Week rank
0
IOCs

WhiteSnake is a stealer with advanced remote access capabilities. The attackers using this malicious software can control infected computers and carry out different malicious activities, including stealing sensitive files and data, recording audio, and logging keystrokes. WhiteSnake is sold on underground forums and often spreads through phishing emails.

Stealer
Type
Unknown
Origin
1 September, 2023
First seen
17 January, 2025
Last seen

How to analyze WhiteSnake with ANY.RUN

Type
Unknown
Origin
1 September, 2023
First seen
17 January, 2025
Last seen

IOCs

IP addresses
81.187.79.8
104.238.189.120
74.48.4.144
164.132.115.9
47.110.140.182
168.138.211.88
5.78.68.6
74.208.179.68
216.39.242.18
23.224.102.6
129.151.109.160
47.96.78.224
121.63.250.132
45.61.136.13
178.236.246.50
206.189.109.14
38.60.191.38
109.123.247.164
217.145.238.175
18.218.18.183
Domains
traffik-filtrados.info
vosn.at
Last Seen at
Last Seen at

Recent blog posts

post image
Malware Trends Overview Report: 2024
watchers 4958
comments 0
post image
YARA Rules: Cyber Threat Detection Tool for M...
watchers 680
comments 0
post image
Threat Intelligence Pivoting: Actionable Insi...
watchers 557
comments 0

What is WhiteSnake malware?

WhiteSnake is a stealer malware whose activity was first observed in early 2023. This malware is designed to infiltrate computer systems and exfiltrate a variety of sensitive information to the attacker’s servers, including saved passwords, autofill information, and browsing history.

WhiteSnake operates as a malware-as-a-service (MaaS), a business model where the developers offer the malware to other cybercriminals for a fee. In the case of WhiteSnake, the developers provide a subscription service for several hundred dollars.

According to the threat intelligence researcher @RussianPanda9xx, the malware’s notable feature is the support of different payload formats like BAT, MSI, SCR, etc.

The distribution and sale of WhiteSnake primarily occurs on DarkWeb forums and Telegram. The availability of the malware contributes to its spread and increases its potential impact.

WhiteSnake has been distributed through various vectors like phishing campaigns, where unsuspecting users are tricked into downloading the malware, and even through open-source repositories.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

WhiteSnake malware execution process

Let’s upload a sample of WhiteSnake to the ANY.RUN sandbox.

WhiteSnake analysis in ANY.RUN WhiteSnake analysis in ANY.RUN sandbox

WhiteSnake first performs anti-VM checks to detect if it is running in a virtual environment or sandbox. It does this by querying the Windows Management Instrumentation (WMI) to retrieve the "Manufacturer" and "Model" properties of the system. It then checks if any of these properties contain strings associated with virtual machines or sandboxes, such as "virtual," "vmware," "virtualbox," etc. If any of these strings are detected, the malware will exit to avoid analysis.

WhiteSnake process graph in ANY.RUN WhiteSnake process graph demonstrated by ANY.RUN sandbox

The malware in our task performs system discovery and uses the command line to display information about available Wi-Fi networks, including SSID, BSSID, and signal strength. It also checks if a mutex (a synchronization object) is already present to prevent multiple instances of the malware from running simultaneously. In our sample, the mutex is "lcy9igxycx."

Then WhiteSnake proceeds to gather sensitive information from the infected system. This includes:

  • Browsing data (cookies, autofill, login data, history, etc.) from various web browsers like Chrome, Firefox, Edge, etc.
  • Cryptocurrency wallet data from popular wallets like Ledger, Atomic, Wasabi, Binance, etc.
  • Cryptocurrency browser extension data from extensions like MetaMask, Ronin, Binance Chain, etc.
  • Other system information like username, computer name, etc.

The gathered information is then encrypted and uploaded to one of the attacker-controlled servers specified in the malware's configuration.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

WhiteSnake stealer technical details

Let’s sum up what the WhiteSnake stealer is capable of. Thanks to its remote command execution functionality. attackers can remotely control the infected system and perform various malicious activities that include:

  • Pulling data from browsers, including Chrome and Firefox, and File Transfer Protocol (FTP) clients.
  • Taking screenshots of the infected system, providing attackers with visual information about the user's activities.
  • Recording audio using the machine's microphone.
  • Taking shots using the web camera.
  • Capturing victims’ keystrokes, which lets attackers discover their login credentials, credit card numbers, and other sensitive information entered by the user.
  • Stealing dozens of crypto wallets, including popular extensions like MetaMask and Phantom, and desktop wallets like Exodus.

One of the key features of this malware is its use of mutex to avoid running on systems that have already been infected. This helps prevent detection and conflict with other instances of the malware.

It is also designed to avoid analysis in a sandbox or virtual machine. The malware includes anti-VM functionality that allows it to detect when it is running in a virtual environment and stop its operation.

WhiteSnake can maintain persistence on the infected system. It automatically runs via a scheduled task, ensuring that it remains active even after the system is restarted.

WhiteSnake malware distribution methods

As mentioned, WhiteSnake is distributed through various methods. However, as with most stealers, including Stealc and Amadey, phishing emails with malicious attachments and links constitute the most widespread vector of attack. In one campaign, criminals leveraged fake documents masquerading as official correspondence from a government agency.

In another attack, threat actors attempted to spread the WhiteSnake stealer through the open-source Python Package Index repository. Attackers uploaded malicious code hoping it would be downloaded and executed by unsuspecting users.

Given that WhiteSnake is a MaaS, available for purchase to various criminals, it is likely that new methods of distributing this threat will be used by criminals in the future.

Conclusion

WhiteSnake is a relatively new but serious cybersecurity threat for organizations worldwide. To prevent infection, it's important to have good security measures in place. One important part of a strong security plan is using a malware analysis sandbox.

ANY.RUN’s interactive sandbox has many features that make analyzing malware easier and faster. It can:

  • Identify threats in files and URLs in less than 40 seconds.
  • Let you interact with samples and the system, just like on a regular computer.
  • Give you customizable Windows and Linux virtual machines to fit your needs.
  • Create detailed reports that explain the threats that were found.
  • Show all activities related to the network, registry, files, and processes.

Create your FREE ANY.RUN account today!

HAVE A LOOK AT

Arechclient2 screenshot
Arechclient2
arechclient2
The Arechclient2 malware is a sophisticated .NET-based Remote Access Trojan (RAT) that collects sensitive information, such as browser credentials, from infected computers. It employs various stealth techniques, including Base64 encoding to obscure its code and the ability to pause activities to evade automated security tools. The malware also can adjust Windows Defender settings and uses code injection to manipulate legitimate processes.
Read More
Havoc screenshot
Havoc
havoc
Havoc is an advanced post-exploitation framework used by hackers to take control of a system once they've breached it. With Havoc, attackers can run commands remotely, inject malicious processes, and access sensitive data. It's often used in targeted attacks, allowing cybercriminals to stay hidden in a network while stealing information or launching further attacks. Its flexibility and ability to bypass detection make it a serious threat, especially in environments that rely on traditional security tools.
Read More
LokiBot screenshot
LokiBot
lokibot loader trojan
LokiBot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.
Read More
Latrodectus screenshot
Latrodectus
latrodectus
Latrodectus is a malicious loader that is used by threat actors to gain a foothold on compromised devices and deploy additional malware. It has been associated with the IcedID trojan and has been used by APT groups in targeted attacks. The malware can gather system information, launch executables, and detect sandbox environments. It uses encryption and obfuscation to evade detection and can establish persistence on the infected device.
Read More
StrelaStealer screenshot
StrelaStealer
strela
StrelaStealer is a malware that targets email clients to steal login credentials, sending them back to the attacker’s command-and-control server. Since its emergence in 2022, it has been involved in numerous large-scale email campaigns, primarily affecting organizations in the EU and U.S. The malware’s tactics continue to evolve, with attackers frequently changing attachment file formats and updating the DLL payload to evade detection.
Read More
Agent Tesla screenshot
Agent Tesla
agenttesla trojan rat stealer
Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.
Read More