Researchers detailed ongoing Snake Keylogger activity in which attackers deliver the .NET-based infostealer through phishing emails carrying archive files, malicious executables, exploit-laden RTF documents abusing CVE-2017-11882, and Excel attachments with password-protected VBA macros. In one analyzed chain, a lure such as SeptemberOrderlist.pdf.exe decrypted intermediate .NET assemblies before launching the final payload, while another used base64-encoded PowerShell to download a Snake downloader, retrieve an RC4-encrypted DLL, and deploy the malware through process hollowing.
Snake is designed to steal credentials and other sensitive data from more than 50 applications, including browsers, email and FTP clients, communication tools, wireless profiles, and Windows product information, while also capturing keystrokes, screenshots, clipboard contents, host details, geolocation, and time data. The malware can persist through scheduled tasks or Startup-folder registry changes, evade defenses by killing security tools, adding Windows Defender exclusions, and deleting itself, and exfiltrate stolen data over SMTP, FTP, or Telegram via HTTPS. Multiple researchers said Snake shares strong code and loader similarities with commodity stealers such as FormBook, Agent Tesla, Matiex, 404, Cheetah, and Phoenix, pointing to code reuse or shared tooling in the cybercrime ecosystem.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Cybereason reported a spike in Snake infections in late August 2021. The company said it did not observe a clear industry or geographic targeting preference among victims during that period.
HP Wolf Security noted that Snake samples reported to MalwareBazaar in March 2021 used several obfuscators, including ConfuserEx, Beds Protector, DeepSea 4.1, Babel .NET, and NET Obfuscar. This documented active circulation and variation in the malware’s protection methods.
HP Wolf Security and Cybereason both state that Snake, a modular .NET infostealer/keylogger, was first seen in late November 2020. The malware was distributed through spam and phishing campaigns and supported credential theft, keylogging, screenshots, and multiple exfiltration methods.
Cybereason reported that a Snake sample named SeptemberOrderlist.pdf.exe used a multi-stage loader chain with .NET assemblies named representative and CF_Secretaria. The company found this staging mechanism was nearly identical to ones used by FormBook and Agent Tesla, suggesting shared tooling or code reuse.
Fortinet published analysis in November 2021 detailing a fresh Snake Keylogger variant’s infection chain, persistence through Startup-folder registry changes, credential theft, keylogging, screenshot capture, and exfiltration via SMTP, FTP, and Telegram. The report also shared malicious URLs and file hashes as indicators of compromise.
Fortinet said FortiGuard Labs captured a malicious Excel attachment in the wild that delivered a fresh Snake Keylogger variant. The lure used password-protected VBA macros and PowerShell to download a Snake downloader, retrieve an RC4-encrypted DLL, and deploy the payload via process hollowing.
HP Wolf Security published research on Snake in June 2021, describing its delivery via malicious spam, layered unpacking, persistence, process hollowing, and links to other commodity .NET keyloggers such as Matiex, 404, Cheetah, and Phoenix. The report also documented Snake’s use of CVE-2017-11882 in some campaigns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybereason.com
Open sourcefortinet.com
Open sourcethreatresearch.ext.hp.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.