logo

Snake Keylogger in Geopolitical Affairs: Abuse of Trusted Java Utilities in Cybercrime Operations

ID: 7759e862-c401-55e5-a59f-912c275db282

STIX ID: report--7759e862-c401-55e5-a59f-912c275db282

Feed Name: Lab52 Blog

Threat Score
70/100

Date Published: 2025-06-27

Date Updated: 2026-04-28

Author: 3722304989

...
...

This report documents a spearphishing campaign distributing Snake Keylogger—an infostealer offered as MaaS—using zipped attachments that include a legitimate jsadebugd.exe abused for DLL sideloading and injection into InstallUtil.exe; it describes the kill chain, persistence via a Run registry key, broad credential and product key exfiltration over SMTP, and provides IoCs (emails, domains, and multiple file hashes), noting the campaign’s oil-sector lure tied to regional geopolitical events.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.