SnakeStealer is an infostealer malware family, also referred to as Snake Keylogger, first seen in 2019. Early reporting linked it to a threat marketed on underground forums as 404 Keylogger or 404 Crypter before it was rebranded. It operates under a malware-as-a-service model, with operators renting or selling access along with updates and support. ESET reported that in H1 2025 SnakeStealer became the most commonly detected infostealer in its telemetry, accounting for roughly one-fifth of infostealer infections, and noted that its rise was aided by the decline of Agent Tesla, with some underground Telegram channels recommending SnakeStealer as its successor.
Its primary purpose is theft of sensitive information, including login credentials, financial data, cryptocurrency-related information, and other stored secrets from compromised systems. Reported capabilities include keystroke logging, theft of saved credentials and passwords from web browsers, databases, email clients, chat clients including Discord, and Wi-Fi networks, as well as screenshot capture and clipboard collection. The malware is also described as modular and capable of evasion and persistence, including terminating processes associated with security or malware-analysis tools, checking for virtualized environments, and altering Windows boot configurations to maintain persistence.
Observed delivery is primarily via phishing attachments. Payloads have been disguised as password-protected ZIP archives, weaponized RTF files, ISO files, and PDF files. Early variants reportedly used Discord to host payloads downloaded after victims opened malicious email attachments, and abuse of Discord for hosting was described as a hallmark tactic in SnakeStealer campaigns. It has also been distributed bundled with other malware, through pirated software, and via fake applications. Exfiltration methods mentioned in the reporting include FTP, HTTP, email, and Telegram bots. ESET products mainly detect this malware as MSIL/Spy.Agent.AES.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer offered via a malware-as-a-service model that steals credentials and other sensitive data from compromised Windows systems. Its capabilities include evasion, persistence through altered Windows boot configurations, credential theft from browsers, databases, email and chat clients, Wi-Fi credential theft, clipboard capture, screenshots, keylogging, and exfiltration via FTP, HTTP, email, or Telegram bots.
Infostealer in use since 2019 with capabilities including keystroke logging, stealing saved credentials, capturing screenshots, and collecting clipboard data.
Infostealer/keylogger that logs keystrokes, steals saved credentials, takes screenshots, and collects clipboard data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.