Researchers detailed an ongoing Snip3 crypter malware campaign that used spear-phishing emails themed as tax statements to launch a multi-stage infection chain. The attacks began with obfuscated VBScript and PowerShell downloaders that retrieved additional components from remote infrastructure including SQL-backed command sources and public text-hosting services, then established persistence through startup-folder VBS files. Later stages gathered host information, communicated with download servers over HTTP POST, and decrypted further payloads directly in memory to reduce detection.
The final Snip3 stage dynamically compiled C# RunPE code with CodeDom and used process hollowing to inject remote-access trojans into legitimate Windows processes including AppLaunch.exe, RegAsm.exe, and regsvcs.exe. Analysis across samples showed the framework delivering both DcRAT and QuasarRAT, with one examined payload identified as DcRAT through artifacts including its mutex naming, X.509 certificate fields, and the AES salt string DcRatByqwqdanchun. The reporting indicates Snip3 remains an adaptable loader for concealing commodity RATs behind layered scripting, in-memory decryption, and changing command-and-control infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The documented campaign's later stages fetched PowerShell payloads from PasteText, established multiple Startup-folder persistence mechanisms, collected host information, and contacted 185.81.157.59:3333 over HTTP POST. The final Stage-4 Snip3 loader dynamically compiled RunPE code and injected RAT payloads into legitimate processes, with analyzed samples delivering DcRAT via crazydns.linkpc.net:5900.
ThreatLabz documented an ongoing Snip3 campaign beginning with spear-phishing emails themed as tax statements, using attachments including a malicious VBScript. The first-stage script connected to a remote SQL database to reconstruct command components and launch a downloader PowerShell stage.
After extracting and examining the final payload from the Snip3 chain, the analysis concluded it was DcRAT rather than AsyncRAT. The determination was based on indicators including the mutex DcRatMutex_qwqdanchun, the embedded certificate issuer CN "DcRat Server," and the AES salt string "DcRatByqwqdanchun."
A first-stage VBScript sample obtained from MalwareBazaar was analyzed as a multi-stage Snip3 crypter chain. The chain launched PowerShell, fetched a second-stage script from textbin[.]net, established persistence with MicroSoftOutlookLauncher.vbs, and used in-memory compiled RunPE code to inject a final payload into RegSvcs.exe.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.