logo

New SnappyClient Implant Combines Remote Access, Data Theft and Advanced Evasion

ID: e74c2138-ce3f-5285-824c-32476d9c1af7

STIX ID: report--e74c2138-ce3f-5285-824c-32476d9c1af7

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

SnappyClient is a sophisticated Windows infostealer and C2 implant first observed in December 2025 and distributed via fake Telefónica webpages, HijackLoader, and GhostPulse; it harvests browser passwords, cookies and cryptocurrency wallets, provides remote proxies and terminal access, and uses Snappy compression with ChaCha20-Poly1305 for C2 traffic. The implant employs advanced evasion — patching AMSI, using Heaven’s Gate and mapping a clean ntdll — and persistent mechanisms (scheduled tasks, Run keys), and Zscaler telemetry indicates active campaigns focused on cryptocurrency theft; defenders should monitor for unusual scheduled task and registry activity and look for Heaven’s Gate execution patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.