SnappyClient Implant Blends Remote Access, Data Theft, and Stealth Evasion
ID: 8cdecee6-783d-53f4-8862-7eb4f7b28196
STIX ID: report--8cdecee6-783d-53f4-8862-7eb4f7b28196
Feed Name: GBHackers
Zscaler ThreatLabz documents "SnappyClient," a sophisticated C++ C2 implant delivered via the HijackLoader loader (observed in a phishing campaign impersonating Telefónica O2) that performs credential and crypto wallet theft, remote access, and extensive evasion (AMSI bypass, Heaven’s Gate/syscalls, transacted hollowing). The analysis details its encrypted ChaCha20-Poly1305 control/data protocol, embedded and remote configs, wide-ranging theft and remote-control capabilities, code overlaps with HijackLoader, provided SHA256 IOCs, and mitigation recommendations focused on loader detection, AMSI integrity, process-injection behavior, and browser/clipboard monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
