New SnappyClient Implant Combines Remote Access, Data Theft and Advanced Evasion
ID: e74c2138-ce3f-5285-824c-32476d9c1af7
STIX ID: report--e74c2138-ce3f-5285-824c-32476d9c1af7
Feed Name: cybersecurityNews.com
SnappyClient is a sophisticated Windows infostealer and C2 implant first observed in December 2025 and distributed via fake Telefónica webpages, HijackLoader, and GhostPulse; it harvests browser passwords, cookies and cryptocurrency wallets, provides remote proxies and terminal access, and uses Snappy compression with ChaCha20-Poly1305 for C2 traffic. The implant employs advanced evasion — patching AMSI, using Heaven’s Gate and mapping a clean ntdll — and persistent mechanisms (scheduled tasks, Run keys), and Zscaler telemetry indicates active campaigns focused on cryptocurrency theft; defenders should monitor for unusual scheduled task and registry activity and look for Heaven’s Gate execution patterns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
