SnappyClient is a C++ command-and-control implant used to maintain persistent access, remotely control infected systems, and steal data, including information from browsers, applications, extensions, and crypto wallets. Research from Zscaler ThreatLabz and follow-on reporting show the malware supports capabilities such as screenshot capture, keylogging, remote shell access, and broad data exfiltration, while also using multiple evasion techniques to reduce detection. Those techniques include an AMSI bypass, 64-bit execution support, direct system calls, and code injection into legitimate processes.
Observed delivery chains used HijackLoader to deploy SnappyClient, including campaigns involving a fake Telefónica/O2 website targeting German-speaking users and additional intrusions linked to ClickFix and GhostPulse-style activity. Zscaler's analysis also found the malware stores a plaintext JSON configuration in the binary and uses hooks on LoadLibraryExW, AmsiScanBuffer, and AmsiScanString to force clean AMSI results. The reporting indicates SnappyClient emerged in late 2025 and is notable as a flexible, stealth-oriented implant that combines remote administration, surveillance, and theft functions in a single framework.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
A SnappyClient version 0.1.22 sample compiled on April 2, 2026 used a 32-bit intermediary loader delivered by HijackLoader to unpack and self-hollow the RAT payload. Reverse engineering found matching runtime structures, CRC-32 code, configuration format, API-resolution order, syscall logic, and dead code, supporting the conclusion that the loader was compiled from HijackLoader source code; later 0.1.29 versions were loaded directly by HijackLoader.
On March 18, 2026, Zscaler ThreatLabz published a technical analysis detailing SnappyClient's capabilities, including AMSI bypass, persistence, encrypted custom TCP command-and-control, browser and wallet theft, keylogging, screenshots, remote shell access, and reverse proxy features. The researchers assessed the operation as financially motivated and focused on cryptocurrency theft, and noted code and tradecraft overlaps with HijackLoader suggesting a possible link between the malware families.
ThreatLabz observed SnappyClient being delivered through HijackLoader in multiple intrusion chains, including a fake Telefónica/O2 website targeting German-speaking users and a ClickFix-based GhostPulse/HijackLoader infection flow. These delivery methods showed operators using varied social engineering and loader-based distribution tactics.
Zscaler ThreatLabz reported that the SnappyClient malware family was first seen in December 2025. It was identified as a modular command-and-control implant used for stealthy persistence, surveillance, remote access, and data theft.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
neso.re
Open sourcezscaler.com
Open sourcedarkreading.com
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.