Matiex is a Windows-based .NET keylogger and information-stealing malware sold on underground forums as a commodity malware offering. It has been marketed with multiple operator-friendly features, including configurable installation behavior, startup persistence, self-removal, and several exfiltration options. The malware is associated with the broader ecosystem of commodity .NET stealers and keyloggers, and multiple analyses have noted strong code and architectural similarities between Matiex and Snake Keylogger, with some reporting that Snake likely shares a common code base or may have evolved from Matiex. Matiex has also appeared as a payload in phishing-delivered malware campaigns alongside other commodity stealers such as Agent Tesla, FormBook, Azorult, and njRat.
Matiex is designed primarily for surveillance and theft of user data. Reported capabilities include Unicode keystroke logging, clipboard capture, screenshot collection, microphone recording, password and sensitive-data theft from more than 60 browsers, victim IP discovery, and remote upload of stolen information. Exfiltration channels advertised or observed for Matiex include FTP, SMTP or email, Telegram, Discord, and in some reporting HTTP. The malware also supports persistence on Windows through startup mechanisms and includes a self-destruction feature intended to remove the malware after an operation is complete. Some reporting indicates support for binder-style execution, allowing the malware to be packaged with other files so it runs when those files are opened.
Observed delivery has included spam email carrying malicious attachments, including archive files masquerading as legitimate content. Matiex has also been identified as a final payload in broader phishing campaigns using malicious Office documents and staged droppers. Its packaging, sales model, and support structure are consistent with malware-as-a-service commercialization aimed at a wide range of criminal operators rather than a narrowly targeted intrusion set.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
A common factor of the operation’s second-stage samples is the usage of steganography to obfuscate their malicious intent.
Now let’s reverse a .NET file which was extracted from a legitimate looking zip file “ window-defender-update.zip ”
This KeyboardLoggerTimer is the basic feature that all the Keyloggers have. This is used by the malware to record any interaction with the keyboard without the victim’s knowledge.
Another important feature is the ScreenshotLoggerTimer which can take screenshots of your system automatically at specified time intervals.
The ClipboardLoggerTimer in Matiex Keylogger is one of the key features as important pieces of information such as complex login credentials are copied and pasted in registration forms, login pages and using this feature confidential information can be retrieved from the victim’s system.
All these data will be encrypted and uploaded to the remote, attacker controlled servers via FTP, HTTP or Email.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A closely related earlier/similar malware compared against Snake Keylogger, sharing bitmap/resource loading, dynamic module loading, persistence, keylogging and information-stealing behavior.
A malware family whose code is described as highly similar to Snake's information-stealing features, suggesting code reuse or shared lineage.
A .NET keylogger sold with a builder/service model and assessed in the content as likely sharing the same code base with Snake. It includes overlapping process-killing, self-removal, keystroke exfiltration, Telegram exfiltration, and GeoIP/orientation functions; it also reportedly supports audio recording and Discord exfiltration.
Observed as one of the final payload malware families delivered by the campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.