logo

C2 Implant 'SnappyClient' Targets Crypto Wallets

ID: 155a6bff-36c0-5b23-b802-32abdd0d1f77

STIX ID: report--155a6bff-36c0-5b23-b802-32abdd0d1f77

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2026-03-18

Date Updated: 2026-04-21

Author: Jai Vijayan

...
...

Zscaler ThreatLabz analyzed 'SnappyClient', a C++ command-and-control implant first observed in December 2025 that provides stealthy, persistent remote access and data-theft capabilities (screenshots, keylogging, credential and cookie theft, remote shell). The malware uses advanced evasion (AMSI bypass, 64-bit direct system calls, process injection), is delivered via the modular 'HijackLoader' and social-engineering (fake Telefonica site, ClickFix), encrypts C2 traffic with ChaCha20-Poly1305, and persists via scheduled tasks or registry autorun, with primary observed use in cryptocurrency theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.