Researchers detailed how Snake Keylogger—also tracked as 404 Keylogger—continues to spread through multi-stage infection chains that begin with phishing documents or other loaders and end in credential theft, surveillance, and data exfiltration. One analyzed campaign used a malicious Microsoft Word file with VBA macros that dropped an .inf file into %TEMP% and abused LaunchINFSectionW from Advpack.dll to execute the next stage through legitimate Windows components. That chain then used built-in tools to reconstruct and launch a disguised DLL downloader, which attempted to fetch an additional payload from a remote command-and-control endpoint.
Separate technical analyses describe Snake as a long-running malware-as-a-service operation with modular .NET payloads, in-memory decryption, steganographic extraction of components, and execution techniques including process injection and process hollowing. The malware is designed to steal browser, email, FTP, Discord, and Wi-Fi credentials; log keystrokes; capture screenshots and clipboard data; profile infected hosts; and evade analysis through anti-debugging checks and termination of security tools. Researchers also reported persistence through registry keys, startup items, or scheduled tasks, and exfiltration over channels including Telegram, SMTP, and FTP, while linking the family to variants such as Matiex, Cheetah, and Nova.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
ASEC reported a phishing campaign using emails disguised as project proposals to deliver a compressed attachment containing obfuscated JavaScript. The script launched PowerShell, decrypted an embedded SnakeKeylogger payload for in-memory execution, and the report published associated SMTP/Telegram exfiltration infrastructure and an MD5 hash.
A later intelligence report documented Snake's evolution across variants including Matiex, Cheetah, Nova, and VIP/basic Snake, and published ATT&CK-mapped TTPs, detection opportunities, and indicators of compromise.
A technical and intelligence analysis states that Snake Keylogger, also known as 404 Keylogger, has been active since at least 2019 and marketed through underground markets and Telegram as malware-as-a-service.
A 2024 analysis reported that Snake Keylogger remained active in 2024 and detailed a multi-stage chain involving in-memory decryption/loading, process hollowing, credential theft, keylogging, screenshot capture, clipboard theft, registry persistence, and exfiltration via SMTP, FTP, and Telegram.
Another analysis describes Snake Keylogger as a .NET-based information-stealing malware family first observed in late 2020, documenting its multi-stage execution, persistence, anti-analysis, and exfiltration behavior.
During the same macro-chain analysis, the executed 32-bit downloader was found attempting to retrieve a further payload from vybsnf3p.sa.com/fdsfh.exe, but the server was reportedly down and returned HTTP 404 at the time of analysis.
An analysis published on 2024-02-07 examined a SnakeKeylogger infection chain delivered through a malicious Word document with VBA macros. The document wrote an INF file to %TEMP%, abused Advpack.dll's LaunchINFSectionW to execute it, and used built-in Windows tools to extract and run a downloader DLL disguised with a .jpg filename.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourcerexorvc0.com
Open sourceany.run
Open sourcezw01f.github.io
Open sourceany.run
Open sourcefarghlymal.github.io
Open sourceany.run
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.