Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Chinese Hackers Use AI Agents to Automate Web Server Attacks
August 21, 2026
Agent Tesla Malware Hides in Unicode Emojis to Evade Detection
August 21, 2026
Critical GitLab Code Injection Flaw CVE-2023-5006 Actively Exploited
August 21, 2026
Home/Threats/SnappyClient Malware Combines Remote Access, Data Theft, and Evasion
Threats

SnappyClient Malware Combines Remote Access, Data Theft, and Evasion

Key Takeaways A new sophisticated malware, SnappyClient, has emerged, combining remote access, data theft, and advanced evasion techniques. The primary attack vector involves deceptive websites,...

Marcus Rodriguez
Marcus Rodriguez
March 19, 2026 4 Min Read
53 0

Key Takeaways

  • A new sophisticated malware, SnappyClient, has emerged, combining remote access, data theft, and advanced evasion techniques.
  • The primary attack vector involves deceptive websites, initially impersonating Telefónica, targeting German-speaking users with HijackLoader to deliver SnappyClient.
  • SnappyClient specifically targets a wide array of web browsers and cryptocurrency wallets for credential and financial data exfiltration.
  • The malware employs advanced evasion tactics, including AMSI bypass and Heaven’s Gate, making detection and analysis challenging for security tools.
  • Persistence mechanisms involve scheduled tasks and registry run keys, with all sensitive files encrypted on disk.

A formidable new threat, dubbed SnappyClient, is actively targeting Windows users, consolidating a dangerous arsenal of remote access capabilities, data theft mechanisms, and sophisticated evasion techniques within a single, compact C++ implant. This malware, first detected in December 2025, operates as a command-and-control (C2) framework implant, capable of logging keystrokes, capturing screenshots, initiating remote terminals, and exfiltrating sensitive data from various browsers and applications, all while adeptly circumventing common security defenses.

Table Of Content

  • Key Takeaways
  • Initial Infection Vectors
  • Technical Analysis and Communication
  • Extensive Data Theft Capabilities
  • Inside SnappyClient’s Evasion and Persistence
  • What You Should Do

Initial Infection Vectors

The initial compromise typically begins with a highly convincing fake website designed to impersonate Telefónica, a prominent telecommunications firm. German-speaking individuals who navigate to this fraudulent page are automatically served a download for HijackLoader. Upon execution, HijackLoader decrypts and injects SnappyClient directly into memory, bypassing disk-based detection.

A secondary distribution method for SnappyClient was observed in early February 2026. This method leveraged a “ClickFix” social engineering tactic disseminated via X (formerly Twitter), which similarly deployed SnappyClient through a combination of GhostPulse and HijackLoader.

Technical Analysis and Communication

Researchers at Zscaler ThreatLabz identified SnappyClient during their ongoing monitoring of HijackLoader activity in December 2025. Their detailed analysis revealed that SnappyClient communicates with its C2 server using a proprietary TCP-based protocol. Each message exchanged is compressed using the Snappy algorithm and then encrypted with ChaCha20-Poly1305, significantly complicating network traffic inspection for security analysts.

Extensive Data Theft Capabilities

SnappyClient exhibits a broad targeting scope for data theft, focusing on ten popular web browsers, including Chrome, Firefox, Edge, Opera, and Brave. From these, it harvests saved passwords, session cookies, and complete browser profiles. Beyond standard browser data, the malware specifically targets numerous cryptocurrency-related extensions, such as MetaMask, Phantom, TronLink, Coinbase Wallet, and TrustWallet. Furthermore, standalone cryptocurrency applications like Exodus, Atomic, Electrum, and Ledger Live are also in its crosshairs. Network traffic analysis confirms that the primary financial objective of these campaigns is the illicit acquisition of cryptocurrency.

In addition to direct data exfiltration, SnappyClient establishes reverse proxies for FTP, VNC, SOCKS5, and RLOGIN, providing attackers with diverse pathways into compromised networks. The malware also actively monitors clipboard content, silently replacing Ethereum wallet addresses to redirect cryptocurrency transactions. Its operational flexibility is enhanced by two dynamic configuration files, EventsDB and SoftwareDB, pushed by the C2 server. These files dictate which applications to target and what actions to perform, enabling attackers to adapt the malware’s behavior without requiring a full redeployment.

Inside SnappyClient’s Evasion and Persistence

SnappyClient’s resilience stems from its sophisticated ability to neutralize common security controls. From its initial execution, the implant hooks the Windows LoadLibraryExW function, meticulously monitoring for any attempts to load amsi.dll. When detected, it patches AmsiScanBuffer and AmsiScanString to consistently return a “clean” result, effectively disabling Windows’ Antimalware Scan Interface (AMSI) without triggering any alerts.

To circumvent user-mode API hooks implemented by endpoint security products, SnappyClient employs a technique known as Heaven’s Gate. This method involves switching execution between 32-bit and 64-bit modes to issue direct system calls, thereby bypassing the monitored API layers. It further enhances its stealth by mapping a clean copy of ntdll.dll into memory, allowing it to access core Windows functions without interference. These evasion patterns bear a strong resemblance to HijackLoader’s design, suggesting a potential connection between the developers of both malware families.

For persistence, SnappyClient initially attempts to register a scheduled task that activates upon every user logon. Should this method fail, it establishes an autorun entry under the SoftwareMicrosoftWindowsCurrentVersionRun registry key. The implant copies itself to a predefined path, launches from this new location, and then terminates its original process. All sensitive files stored on disk, including the keylogger file, EventsDB, and SoftwareDB, are encrypted using ChaCha20, significantly hindering forensic recovery efforts.

What You Should Do

  • Exercise extreme caution when downloading executable files, especially from unverified websites, even if they appear to represent reputable brands.
  • Implement robust email and web filtering to block access to known malicious sites and prevent the delivery of phishing attempts.
  • Security teams should actively monitor for the creation of unusual scheduled tasks and suspicious modifications to registry run keys, as these are early indicators of SnappyClient’s persistence mechanisms.
  • Deploy endpoint detection and response (EDR) solutions capable of identifying advanced evasion techniques, such as Heaven’s Gate execution patterns and transacted hollowing behavior.
  • Regularly update web browsers to mitigate vulnerabilities that could be exploited for App-Bound Encryption bypasses.
  • Periodically audit installed browser extensions, particularly those associated with cryptocurrency wallets, and remove any that are unfamiliar or unnecessary.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarePatchSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Cisco ASA, FTD Critical Zero-Day Actively Exploited for Interlock Ransomware

Next Post

WaterPlum Distributes StoatWaffle Malware in VSCode Supply Chain Attack

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
US Bank Investigates LockBit Ransomware Attack Claiming Data Theft
August 21, 2026
Critical N-able Passportal Flaw Exposes Password Vaults, 2FA Codes
August 21, 2026
Sandworm Exploits OAuth, WhatsApp to Hijack High-Value Accounts
August 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us