logo

Beyond the Hook: Unmasking SnappyClient, the HijackLoader-Linked Stealth Stealer Targeting Crypto

ID: 40683fba-2733-5edb-bb85-2da06dfd1181

STIX ID: report--40683fba-2733-5edb-bb85-2da06dfd1181

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-25

Date Updated: 2026-04-23

Author: Ddos

...
...

Zscaler ThreatLabz identified SnappyClient, a C++ C2 implant distributed via HijackLoader and observed targeting German-speaking users through a fake telecommunications site; the malware focuses on cryptocurrency theft by monitoring clipboards for Ethereum addresses, stealing browser and wallet-extension data (Chrome, Edge, Firefox, Metamask, Phantom), and providing remote access features (remote shell, hidden VNC browser, reverse FTP). It employs advanced evasion techniques including Heaven's Gate, direct system calls, transacted hollowing, and an AMSI trampoline hook that forces AmsiScanBuffer/AmsiScanString to return clean, communicates with C2 using ChaCha20-Poly1305, and shows structural overlap with HijackLoader suggesting shared development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.