Unboxing Snake - Python Infostealer Lurking Through Messaging Services
ID: 629b18ff-72d9-512a-a7ef-1e6e691a0d27
STIX ID: report--629b18ff-72d9-512a-a7ef-1e6e691a0d27
Feed Name: Cybereason Blog
Cybereason's Threat Analysis describes a Python-based infostealer (referred to as Snake) distributed via social-engineered Facebook messages and public repositories (GitHub/GitLab). The malware family includes three variants (two Python scripts and one PyInstaller executable) that harvest browser cookies and credentials from multiple browsers (notably Coc Coc, Chrome, and Edge), identify victim geolocation via ipinfo.io, maintain persistence via Startup folder, and exfiltrate data to Telegram Bot API, Discord, or repository-listed C2 endpoints; the report also details obfuscation/staging behaviors, possible Vietnamese-language indicators for attribution, MITRE ATT&CK mappings, and recommended defensive controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
