SnakeLogger is a password-stealer malware family observed in multiple malspam campaigns during 2025. The provided reporting consistently places it among password stealer families, and in some summaries alongside RAT families. It has been distributed through email campaigns using social-engineering themes including Reservations, Invoices, Offers, Payments, and Documents, including campaigns written in Italian and targeting Italy. Reported delivery/sample types associated with the campaigns in which SnakeLogger appeared include MSIL executables, WIN32 executables, AutoIT executables, script files, and malware sent via email. TG Soft CRAM reporting lists SnakeLogger activity in campaigns on 28/07/2025 themed "Reservations," 15/08/2025 themed "Invoices," 28/08/2025 themed "Offers," and 14/10/2025 themed "Documents," with additional mention of campaigns themed "Invoices," "Reservations," "Offers," and "Payments" across weekly reporting. VirusTotal content also associates SnakeLogger with the JA4 TLS client fingerprint t10d070600_c50f5591e341_1a3805c3aa63, noted in an example shared with Redline. The content does not provide further high-confidence technical details on internal functionality, persistence, or specific indicators beyond this JA4 fingerprint and campaign themes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SnakeLogger is a password stealer malware family designed to exfiltrate credentials and other sensitive information from victims.
SnakeLogger is a password stealer malware family designed to extract credentials and sensitive data from victims.
Password-stealing malware distributed via malspam campaigns targeting Italy; observed in an email campaign themed around "Invoices" during the week of 2025-08-11 to 2025-08-17.
SnakeLogger is a password stealer malware distributed via malspam, often using document-themed lures. It is designed to steal credentials and sensitive information from victims.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.