Beyond the Hook: Unmasking SnappyClient, the HijackLoader-Linked Stealth Stealer Targeting Crypto
ID: 40683fba-2733-5edb-bb85-2da06dfd1181
STIX ID: report--40683fba-2733-5edb-bb85-2da06dfd1181
Feed Name: securityonline.info
Zscaler ThreatLabz identified SnappyClient, a C++ C2 implant distributed via HijackLoader and observed targeting German-speaking users through a fake telecommunications site; the malware focuses on cryptocurrency theft by monitoring clipboards for Ethereum addresses, stealing browser and wallet-extension data (Chrome, Edge, Firefox, Metamask, Phantom), and providing remote access features (remote shell, hidden VNC browser, reverse FTP). It employs advanced evasion techniques including Heaven's Gate, direct system calls, transacted hollowing, and an AMSI trampoline hook that forces AmsiScanBuffer/AmsiScanString to return clean, communicates with C2 using ChaCha20-Poly1305, and shows structural overlap with HijackLoader suggesting shared development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
