logo

SnakeKeylogger: A Multistage Info Stealer Malware Campaign

ID: 0f1b2106-712f-5ad8-bee8-ae14b1fd9a1d

STIX ID: report--0f1b2106-712f-5ad8-bee8-ae14b1fd9a1d

Feed Name: Seqrite Blog

Threat Score
72/100

Date Published: 2025-03-25

Date Updated: 2026-04-30

Author: Prashil Moon

...
...

**SnakeKeylogger campaign:** Seqrite Labs documents a multi-stage info‑stealer delivered via malicious .img attachments that mounts a virtual drive to run a small .NET downloader which fetches and decodes an in‑memory Stage2 DLL; the payload uses heavy obfuscation, process hollowing (InstallUtil.exe), and in‑memory DLL loading to exfiltrate credentials from browsers, email clients (including Outlook profiles), FTP (FileZilla), and Wi‑Fi configurations, with active malicious payload hosting observed at http://103.72.56.30/PHANTOM/ and several MD5 IOCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.