SnakeKeylogger, also known as 404 Keylogger, is a .NET-based Windows information stealer active since at least late 2020. It steals browser-stored data and system information and includes keylogging functionality. Recent versions have targeted credentials and other data from Chromium- and Gecko-based browsers, email and FTP clients, Discord tokens, payment-card data, Wi-Fi passwords, clipboard contents, and screenshots. The malware has used SMTP and Telegram for data exfiltration, with some variants supporting HTTP, FTP, and Discord webhooks. VIPKeylogger is widely described as a direct variant or rebrand of SnakeKeylogger.
SnakeKeylogger is commonly delivered through phishing emails using business, shipping, project-proposal, purchase-order, invoice, and DHL-themed lures. Observed delivery chains employ malicious Microsoft Office documents with macros, JavaScript, VBScript, and PowerShell downloaders. Operators use obfuscation, encrypted payloads, reflective in-memory loading, legitimate Windows utilities, anti-analysis checks, and process hollowing to evade detection. Persistence has been observed through scheduled tasks and startup execution. SnakeKeylogger has also been distributed by the PureCrypter malware-as-a-service loader. No specific threat actor attribution is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
ASEC recently confirmed that phishing emails disguised as project proposals are being circulated. The body of the email pretends to request that the proposal and confirmed delivery schedule be submitted as soon as possible, and prompts the recipient to download the attached compressed file.
Execution is handled through WMI rather than direct process creation ... infare.Get("Win32_Process").Create(avaram, Null, circumsail, mayas)
When executed, the JavaScript malware executes PowerShell commands...
When executed, the JavaScript malware executes PowerShell commands as shown in [Figure 4].
the first check we need to observe when it comes to office files is the existence of Macros which are used by the TA to execute VBA commands | FlkMT is responsible for building the payload which will be written in TEMP Directory using WHTLE function
The PowerShell script receives encrypted SnakeKeylogger data as an argument from within the JavaScript file, decrypts it, and executes it in memory without saving it to disk. [Figure 3] Part of the obfuscated JavaScript malware [Figure 4] Part of the obfuscated PowerShell script
The extracted assembly ... includes anti-analysis checks ... An encrypted configuration blob in the User Strings heap contains the Telegram bot token and SMTP credentials -- protected by Babel's obfuscation layer
The decoded PowerShell downloads a JPEG image from Cloudinary CDN ... with 1.55 MB of Base64-encoded .NET assembly appended after the image data.
then it will erase his row existence as the process has been executed and delete the 3 dropped files (VN.inf , cvr.tmp, and xhd.jpg)
ruNDLl32 %TEmP%\xhd.jpg,main here the TA uses Rundll32 which is used to run a DLL and execute xhd.jpg and the export function here is main | Snake uses this method to run the Inf file under a legitimate container or process... it calls a function called tAcKs() and this function is defined as LunachINFSectionW from Advpack.dll
A keylogger is a type of software that monitors and records the keystrokes entered on a computer... they are used to steal sensitive information such as authentication credentials, credit card details, and various confidential data entered through the keyboard.
This type of malware steals all kinds of data from the system it infects, including credentials (passwords and cookies) for VPNs, RDP, business services, banking and social media, stored by a variety of apps (including popular browsers like Chrome and Firefox).
Útočník dokonca môže heslá extrahovať na ďalšie použitie.
SnakeKeylogger—an Infostealer—collects various types of information from the infected system, such as web browser data, system information, and keylogging data
A keylogger is a type of software that monitors and records the keystrokes entered on a computer... they are used to steal sensitive information such as authentication credentials, credit card details, and various confidential data entered through the keyboard.
Exfiltration Exfiltration Over C2 Channel T1041 SMTP/HTTP exfiltration
Like the average Infostealer, DarkCloud steals the account credentials of users that have been saved on web browsers, FTP, and email clients. It is also similar to other Infostealers like AgentTesla and SnakeKeylogger as it uses SMTP or the Telegram API to send the collected information to the C&C server.
58 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer/keylogger delivered via phishing emails as a JavaScript attachment. The JavaScript launches PowerShell, which decrypts the SnakeKeylogger payload and executes it in memory. It steals browser data, system information, and keystrokes, then exfiltrates the data via SMTP or Telegram.
A keylogger family also known as 404 Keylogger. In this content it is described as the parent family/variant lineage for VIPKeylogger, with VIPKeylogger adding dual-channel SMTP and Telegram exfiltration.
A keylogger family also known as 404 Keylogger. In this content it is described as the parent family/variant lineage for VIPKeylogger, with VIPKeylogger adding dual-channel SMTP and Telegram exfiltration.
A .NET stealer/keylogger assessed as the stage 3 payload in this chain. It is described as capable of keylogging, credential harvesting from browsers, email and FTP clients, screenshot capture, clipboard monitoring, SMTP exfiltration, and persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.