logo

Unboxing Snake - Python Infostealer Lurking Through Messaging Services

ID: 629b18ff-72d9-512a-a7ef-1e6e691a0d27

STIX ID: report--629b18ff-72d9-512a-a7ef-1e6e691a0d27

Feed Name: Cybereason Blog

Threat Score
70/100

Date Published: 2024-03-05

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason's Threat Analysis describes a Python-based infostealer (referred to as Snake) distributed via social-engineered Facebook messages and public repositories (GitHub/GitLab). The malware family includes three variants (two Python scripts and one PyInstaller executable) that harvest browser cookies and credentials from multiple browsers (notably Coc Coc, Chrome, and Edge), identify victim geolocation via ipinfo.io, maintain persistence via Startup folder, and exfiltrate data to Telegram Bot API, Discord, or repository-listed C2 endpoints; the report also details obfuscation/staging behaviors, possible Vietnamese-language indicators for attribution, MITRE ATT&CK mappings, and recommended defensive controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.