SnakeKeylogger, also known as 404 Keylogger, is a .NET-based information stealer targeting Windows systems. It steals stored credentials and browser data, records keystrokes, and collects system information. Observed versions also capture clipboard contents and screenshots and target email-client and FTP-client credentials, Wi-Fi passwords, payment-card data, and Discord tokens. Stolen information is exfiltrated through SMTP and the Telegram Bot API; some versions additionally support HTTP, FTP, and Discord webhooks. VIPKeylogger is a closely related variant or rebrand.
SnakeKeylogger is distributed through phishing emails using business-themed lures, including project proposals, purchase orders, payment confirmations, and shipping notifications. Infection chains employ malicious Office documents, compressed JavaScript attachments, VBScript, and PowerShell. Delivery stages use obfuscation, encrypted payloads, image-carried data, and reflective .NET loading to conceal execution. Observed deployments execute the payload in memory and use process hollowing into legitimate Windows .NET utilities. Some deployments establish persistence through scheduled tasks or startup scripts. The malware also gathers public-IP and geolocation information, and related variants implement anti-debugging checks.
SnakeKeylogger has been deployed by the financially motivated cybercrime group TA558 in the SteganoAmor campaign, which uses malicious Office attachments, staged scripts, and compromised legitimate infrastructure. SnakeKeylogger infections have used compromised SMTP servers to transmit stolen information. Campaigns distributing the family operate internationally and include activity targeting government, manufacturing, technology, and banking organizations. PureCrypter has also been used to deliver SnakeKeylogger.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attack begins with a phishing email containing an encrypted Excel file that exploits CVE-2017-0199. Upon opening the file, OLE objects are used to trigger the download and execution of a malicious HTA application.
The group continues to exploit the fairly old CVE-2017-11882 in its attack chain. It uses steganography, an obfuscation technique, inside the chains to spread well-known malware used in other attacks in recent years.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Finally, SnakeKeylogger forwards the information it stole to the compromised legitimate SMTP server.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
ASEC recently confirmed that phishing emails disguised as project proposals are being circulated. The body of the email pretends to request that the proposal and confirmed delivery schedule be submitted as soon as possible, and prompts the recipient to download the attached compressed file.
Execution is handled through WMI rather than direct process creation ... infare.Get("Win32_Process").Create(avaram, Null, circumsail, mayas)
When executed, the JavaScript malware executes PowerShell commands...
When executed, the JavaScript malware executes PowerShell commands as shown in [Figure 4].
the first check we need to observe when it comes to office files is the existence of Macros which are used by the TA to execute VBA commands | FlkMT is responsible for building the payload which will be written in TEMP Directory using WHTLE function
The PowerShell script receives encrypted SnakeKeylogger data as an argument from within the JavaScript file, decrypts it, and executes it in memory without saving it to disk. [Figure 3] Part of the obfuscated JavaScript malware [Figure 4] Part of the obfuscated PowerShell script
The extracted assembly ... includes anti-analysis checks ... An encrypted configuration blob in the User Strings heap contains the Telegram bot token and SMTP credentials -- protected by Babel's obfuscation layer
The decoded PowerShell downloads a JPEG image from Cloudinary CDN ... with 1.55 MB of Base64-encoded .NET assembly appended after the image data.
then it will erase his row existence as the process has been executed and delete the 3 dropped files (VN.inf , cvr.tmp, and xhd.jpg)
ruNDLl32 %TEmP%\xhd.jpg,main here the TA uses Rundll32 which is used to run a DLL and execute xhd.jpg and the export function here is main | Snake uses this method to run the Inf file under a legitimate container or process... it calls a function called tAcKs() and this function is defined as LunachINFSectionW from Advpack.dll
A keylogger is a type of software that monitors and records the keystrokes entered on a computer... they are used to steal sensitive information such as authentication credentials, credit card details, and various confidential data entered through the keyboard.
This type of malware steals all kinds of data from the system it infects, including credentials (passwords and cookies) for VPNs, RDP, business services, banking and social media, stored by a variety of apps (including popular browsers like Chrome and Firefox).
Útočník dokonca môže heslá extrahovať na ďalšie použitie.
SnakeKeylogger—an Infostealer—collects various types of information from the infected system, such as web browser data, system information, and keylogging data
A keylogger is a type of software that monitors and records the keystrokes entered on a computer... they are used to steal sensitive information such as authentication credentials, credit card details, and various confidential data entered through the keyboard.
Exfiltration Exfiltration Over C2 Channel T1041 SMTP/HTTP exfiltration
Like the average Infostealer, DarkCloud steals the account credentials of users that have been saved on web browsers, FTP, and email clients. It is also similar to other Infostealers like AgentTesla and SnakeKeylogger as it uses SMTP or the Telegram API to send the collected information to the C&C server.
63 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a payload in separate 2024 campaigns using a comparable delivery chain. The report does not describe its capabilities.
An infostealer/keylogger delivered via phishing emails as a JavaScript attachment. The JavaScript launches PowerShell, which decrypts the SnakeKeylogger payload and executes it in memory. It steals browser data, system information, and keystrokes, then exfiltrates the data via SMTP or Telegram.
A keylogger family also known as 404 Keylogger. In this content it is described as the parent family/variant lineage for VIPKeylogger, with VIPKeylogger adding dual-channel SMTP and Telegram exfiltration.
A keylogger family also known as 404 Keylogger. In this content it is described as the parent family/variant lineage for VIPKeylogger, with VIPKeylogger adding dual-channel SMTP and Telegram exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.