C2 Implant 'SnappyClient' Targets Crypto Wallets
ID: 155a6bff-36c0-5b23-b802-32abdd0d1f77
STIX ID: report--155a6bff-36c0-5b23-b802-32abdd0d1f77
Feed Name: Dark Reading
Zscaler ThreatLabz analyzed 'SnappyClient', a C++ command-and-control implant first observed in December 2025 that provides stealthy, persistent remote access and data-theft capabilities (screenshots, keylogging, credential and cookie theft, remote shell). The malware uses advanced evasion (AMSI bypass, 64-bit direct system calls, process injection), is delivered via the modular 'HijackLoader' and social-engineering (fake Telefonica site, ClickFix), encrypts C2 traffic with ChaCha20-Poly1305, and persists via scheduled tasks or registry autorun, with primary observed use in cryptocurrency theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
