Screenshotter is a lightweight malware utility used to capture periodic screenshots from infected Windows systems and transmit them to attacker-controlled command-and-control infrastructure over HTTP. It has been observed as a dedicated component in multi-stage intrusion chains rather than as a full-featured standalone platform, and its primary role is victim triage and visual surveillance of the desktop prior to delivery of additional payloads.
Screenshotter has been closely associated with TA866, also known as Asylum Ambuscade, in financially motivated campaigns active since at least 2022. In these operations, initial access commonly began through malspam or malvertising, often using JavaScript downloaders and MSI packages. A recurring infection chain involved a downloader stage such as WasabiSeed retrieving a secondary MSI that installed Screenshotter. TA866 appears to have used the screenshots to manually assess victim value and decide whether to continue with follow-on tooling such as AHK Bot, Rhadamanthys, remote access software, or other post-compromise payloads.
Multiple implementations of Screenshotter have been observed, including JavaScript-based, Python-based, and AutoHotKey-based variants. One documented JavaScript variant used a bundled legitimate image-viewing executable to capture the desktop, save the image locally as a JPEG, and then upload it to command-and-control infrastructure. AutoHotKey-based code associated with the malware has included Russian-language comments. The malware’s functionality is narrowly focused on screenshot capture and exfiltration rather than broad host control.
Screenshotter has also appeared in broader cybercriminal delivery ecosystems beyond TA866-exclusive activity. It has been reported in campaigns involving malvertising, including Google Ads abuse, and has been observed delivered alongside or as a companion payload to other malware families such as Rhadamanthys. Victimology linked to TA866-associated Screenshotter activity has included organizations primarily in the United States, with manufacturing notably affected, alongside government and financial services. The malware is best characterized as a surveillance-oriented utility used during early post-compromise assessment on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Screenshotter is a malware family used to generate periodic screenshots from infected systems which are transmitted to the threat actor over HTTP.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Observed as a companion payload delivered alongside Rhadamanthys.
Screenshotter captures periodic screenshots from infected systems and exfiltrates them over HTTP. Variants were observed in JavaScript, Python and AutoHotKey implementations.
A custom screenshot collection utility delivered via MSI. It runs a bundled legitimate IrfanView executable (snap.exe) to capture the desktop to a JPG and then uploads the screenshot to a C2 endpoint.
Mentioned as another malware observed in malvertising campaigns, used here as contextual background for the investigation rather than the main subject.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.