Snip3 is a Windows malware crypter associated with commodity malware delivery and execution chains. It provides adversaries with ready-made payload protection and execution functionality, including obfuscation, staged delivery, hidden PowerShell execution, and process hollowing via RunPE-style injection into legitimate Windows processes. Snip3 has been observed using Visual Basic-based first-stage execution, PowerShell for second-stage execution, and concealed script execution in hidden windows to reduce user visibility. It can download additional payloads from web services, query WMI classes such as Win32_ComputerSystem for host reconnaissance, and support multi-stage infection workflows. Delivery has been linked to phishing emails using both malicious attachments and malicious links, and ATT&CK mappings also associate it with drive-by compromise. Snip3 is used as an enabling component in broader malware operations rather than as the final payload itself, helping operators package, protect, and launch other malware on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware being delivered through phishing or spearphishing emails containing malicious attachments such as Microsoft Office documents, PDFs, RAR/ZIP archives, CHM, ISO, IMG, HTA, LNK, and executable files disguised as documents.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
The content includes multiple examples of PowerShell being used to decode or deobfuscate payloads and commands, such as 'the threat actors deobfuscated encoded PowerShell commands' and 'OilRig macro has run a PowerShell command to decode file contents.'
APT32 used Run keys to execute VBS scripts; NanoCore creates a RunOnce key to execute its VBS scripts each time the user logs on; TA2541 placed VBS files in the Startup folder.
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
Contagious Interview has established persistence using InvisibleFerret malware to place a .bat file in the Startup Folder. TeamTNT has added batch scripts to the startup folder. Storm-1811 has created Windows Registry Run keys that execute various batch scripts to establish persistence on victim devices.
Examples include APT3 placing scripts in the startup folder, APT32 using Run keys to execute PowerShell and VBS scripts, TA2541 placing VBS files in the Startup folder, TeamTNT adding batch scripts to the startup folder, and Smoke Loader adding a script in the Startup folder to deploy the payload.
Contagious Interview has established persistence using InvisibleFerret malware to place a .bat file in the Startup Folder. TeamTNT has added batch scripts to the startup folder. Storm-1811 has created Windows Registry Run keys that execute various batch scripts to establish persistence on victim devices.
Examples include APT3 placing scripts in the startup folder, APT32 using Run keys to execute PowerShell and VBS scripts, TA2541 placing VBS files in the Startup folder, TeamTNT adding batch scripts to the startup folder, and Smoke Loader adding a script in the Startup folder to deploy the payload.
One of my colleagues made a statement recently about how commonplace process injection has become among malware... many adversaries deploying malware have begun using crypters like HCrypt or Snip3 that inject their arbitrary payloads into other arbitrary processes... analyzing a malware payload protected using HCrypt and injected into aspnet_compiler.exe.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
"Obfuscated Files or Information: Binary Padding" (listed under Snip3)
One of my colleagues made a statement recently about how commonplace process injection has become among malware... many adversaries deploying malware have begun using crypters like HCrypt or Snip3 that inject their arbitrary payloads into other arbitrary processes... analyzing a malware payload protected using HCrypt and injected into aspnet_compiler.exe.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
"Virtualization/Sandbox Evasion: Time Based Checks" (listed under Snip3)
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that executes PowerShell scripts in hidden windows.
Mentioned as another crypter that can inject arbitrary payloads into processes; referenced for comparison rather than as the analyzed sample.
Loader that uses a PowerShell script for second-stage execution.
Malware executed through downloaded Visual Basic files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.