Snip3 Crypter
ID: a3d835ee-e7d0-5cac-9ea1-6e22cdb048e3
STIX ID: report--a3d835ee-e7d0-5cac-9ea1-6e22cdb048e3
Feed Name: Zscaler Security Research Blog
Threat Score
**Executive summary:** The report analyzes the Snip3 crypter campaign that uses spearphishing lures and a multi-stage VBScript/PowerShell chain to deploy RAT loaders (DcRAT and QuasarRAT); it documents in-memory decryption, dynamically compiled RunPE process-hollowing, persistent VBS dropper behaviors, and includes concrete IOCs (C2 IPs/domains, mutex values, filenames).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
