Technical Analysis of SnappyClient
ID: d801359c-a100-533b-8f2f-9a82665e82fc
STIX ID: report--d801359c-a100-533b-8f2f-9a82665e82fc
Feed Name: Security Boulevard
Date Published: 2026-03-18
Date Updated: 2026-04-22
Author: Muhammed Irfan V A (Security Researcher II)
Zscaler ThreatLabz describes SnappyClient, a sophisticated C2 implant deployed via HijackLoader that performs keylogging, screenshot capture, remote shell, and extensive browser/app credential and crypto-wallet theft; it uses advanced evasion (AMSI bypass, Heaven’s Gate, direct syscalls, transacted hollowing), a custom ChaCha20-Poly1305 encrypted protocol with modular configuration from C2, and includes IOCs (file hashes, C2 IPs/ports) and MITRE mappings, indicating active criminal campaigns targeting cryptocurrency users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
