Snake Keylogger, also known as 404 Keylogger, is a modular .NET information-stealing malware family centered on credential theft and keystroke capture on Windows systems. Active since at least 2020 and reported in malware-as-a-service and subscription-style criminal ecosystems, it has evolved from a straightforward keylogger into a broader stealer that targets browser-stored credentials and other sensitive application data. It is widely used in commodity phishing operations and has appeared alongside other crimeware families in campaigns run by both low-sophistication operators and more organized threat clusters.
The malware commonly uses multi-stage delivery and execution chains. Observed infections include phishing and spearphishing campaigns using malicious archives, Office or PDF lures, script-based downloaders, and disguised loader stages. Snake Keylogger has also been delivered by third-party loaders and crypter services, including campaigns using DLL sideloading, AutoIt or Lua-based loaders, and fileless in-memory execution. Some campaigns have used business, tax, shipping, payment, or oil-sector themes, and targeting has included sectors such as defense, aerospace, hospitality, and oil-related organizations.
On compromised hosts, Snake Keylogger steals credentials and other data from web browsers and a range of desktop applications, including mail clients, FTP clients, messaging tools, VPN and SSH-related software, and similar user applications. Reported capabilities include keylogging, clipboard monitoring, screenshot capture, collection of system and geolocation information, and theft of browser cookies. Variants have used process injection into legitimate .NET-related processes and runtime string or import deobfuscation to hinder analysis. Anti-analysis features reported across samples include anti-debugging, anti-VM checks, sandbox evasion, and other environment checks.
Persistence mechanisms observed for Snake Keylogger include scheduled tasks and startup-folder execution. Exfiltration has been reported over multiple channels, including SMTP, HTTP, FTP, and Telegram-based workflows, depending on the build. Related or overlapping variants and branding include 404 Keylogger and samples identified as Best Private LOGGER, the latter assessed as a Snake Keylogger variant based on shared collection logic and coding patterns. Snake Keylogger remains a prevalent Windows credential stealer and keylogger in phishing-led intrusions and commodity malware distribution chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Overview Snake Keylogger, also known as 404 Keylogger, is malware that has been categorized as a keylogger and that has evolved over time, acquiring stealer capabilities that complement its functions and have made it more powerful over the years.
Overview Snake Keylogger, also known as 404 Keylogger, is malware that has been categorized as a keylogger and that has evolved over time, acquiring stealer capabilities that complement its functions and have made it more powerful over the years.
... TA2715 and TA2536, both of which favored Snake Keylogger ...
... TA2715 and TA2536, both of which favored Snake Keylogger ...
“The S2 Group’s intelligence team has identified… a new phishing campaign by Snake Keylogger, a Russian origin stealer programmed in .NET… The campaign… using spearphishing emails offering oil products… [and] the Sideloading Dll technique to load Snake Keylogger…”
“The S2 Group’s intelligence team has identified… a new phishing campaign by Snake Keylogger, a Russian origin stealer programmed in .NET… The campaign… using spearphishing emails offering oil products… [and] the Sideloading Dll technique to load Snake Keylogger…”
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Snake extracts Wi-Fi profile information and passwords using netsh commands
Malicious Excel spreadsheets (.xls) that drop a second .xls to trigger VBA macros
Persistence is established through startup-folder batch scripts and code injection into explorer.exe... The payload is injected into MSBuild.exe or Aspnet_compiler.exe via process hollowing for fileless execution
Inside the archive sits an obfuscated JavaScript file. It hides in heavy junk code and uses control-flow flattening to defeat analysis.
Persistence is established through startup-folder batch scripts and code injection into explorer.exe... The payload is injected into MSBuild.exe or Aspnet_compiler.exe via process hollowing for fileless execution
The payload is injected into MSBuild.exe or Aspnet_compiler.exe via process hollowing for fileless execution
it can use other legitimate processes that are commonly related to .NET (csc.exe, applaunch.exe, installutil.exe, etc.)
their main goal is usually to deobfuscate code and launch the next version or to download the next stage
RegAsm.exe / RegSvcs.exe / InstallUtil.exe abused via process hollowing/injection by AgentTesla and Snake Keylogger
RegAsm.exe / RegSvcs.exe / InstallUtil.exe abused via process hollowing/injection by AgentTesla and Snake Keylogger
Snake uses specific IP addresses to check for monitoring or analysis. If these IPs are detected, the malware alters its behavior to avoid detection.
It also regularly monitors and logs the title of the active window in the foreground using APIs like GetForegroundWindow() and GetWindowText()
[TA0007][T1049] System Network Connections Discovery
System information gathering (hostnames, HW information, etc)
143 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Keylogger malware family listed among the payloads supported by Cruciferra.
Keylogger mentioned in comparative tables of infection vectors, targeted industries, IOCs, and exfiltration channels, but not profiled as a main focus.
Keylogger malware distributed via Cruciferra.
Credential-stealing keylogger delivered as a final payload by the TTF Trap campaign; the 'Best Private LOGGER' variant matches Snake Keylogger collection code.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.