Technical Analysis of SnappyClient
ID: d5c1de2b-5a08-5a2b-a6f2-626aef8e630f
STIX ID: report--d5c1de2b-5a08-5a2b-a6f2-626aef8e630f
Feed Name: Zscaler Security Research Blog
This report provides a technical analysis of SnappyClient, an advanced infostealer observed in eCrime campaigns that steals browser data, extension data (notably crypto wallet extensions), and system artifacts; it details the attack chain (often delivered via a HijackLoader loader and fake websites), embedded plaintext and encrypted configurations, AMSI bypass, process injection techniques (including Heaven's Gate and transacted hollowing), a custom ChaCha20-Poly1305 encrypted/compressed network protocol, supported commands (file exfiltration, remote shells, proxies, HVNC), and observed targeting focused on cryptocurrency theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
