SnappyClient, also tracked as SilabRAT, is a C++ Windows remote-access trojan and command-and-control implant first observed in December 2025. It is designed for persistent post-compromise access, surveillance, data theft, and financially motivated cryptocurrency theft. It can capture screenshots, log keystrokes, provide remote shell and remote file-browsing functions, manage processes and files, execute files, steal browser passwords, cookies, profiles, extensions, and application data, and exfiltrate collected information. It also supports reverse-proxy services including VNC, SOCKS5, FTP, and RLOGIN.
SnappyClient targets browser and cryptocurrency activity, including wallet extensions and cryptocurrency applications, and can monitor clipboard content and cryptocurrency-related window titles. It can obtain Chromium encryption material through process-hollowing techniques to bypass Chromium App-Bound Encryption protections. The implant communicates through a custom TCP protocol using Snappy compression and ChaCha20-Poly1305 encryption, and can receive updated configuration and target definitions from its command-and-control infrastructure.
The malware employs AMSI bypassing, direct system calls via Heaven’s Gate, clean system-library mapping, process injection or transacted hollowing, and other anti-analysis measures. Persistence is established using scheduled tasks or Windows autorun mechanisms. Observed intrusion chains have used HijackLoader to deploy SnappyClient, including fake telecommunications-themed download sites, ClickFix social engineering, and spear-phishing campaigns using trojanized installers and DLL side-loading. Code and tradecraft overlaps with HijackLoader have been observed, although a common developer relationship has not been conclusively established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Victims usually meet a ClickFix prompt through phishing, malicious ads, or compromised websites.
Group-IB observed SilabRAT spreading through email spam and ClickFix social engineering. Victims usually meet a ClickFix prompt through phishing, malicious ads, or compromised websites.
It can also escalate privileges through a known UAC bypass and set up persistence via registry keys or scheduled tasks.
a user was tricked into running a malicious PowerShell command
The Blackpoint SOC received alerts for suspicious powershell.exe usage by a user who fell for a ClickFix-style (Win+R) attack.
Attackers can use the implant to establish a remote shell on compromised systems for direct command-line access.
“Both the loader and HijackLoader build their syscall table the same way: read ntdll.dll from disk, walk the export directory, keep every export whose name begins with Zw, and pull the service number out of the function body.”
It can also escalate privileges through a known UAC bypass and set up persistence via registry keys or scheduled tasks.
It can also escalate privileges through a known UAC bypass and set up persistence via registry keys or scheduled tasks.
Its author has teased plans to inject code into Electron-based apps, including the Ledger and Trezor wallet managers.
“The loader marks its own image writable, zeroes it and then calls into the function that is responsible for mapping the final payload in its place. From this point on the process is executing out of memory it has just erased.”
It can also escalate privileges through a known UAC bypass and set up persistence via registry keys or scheduled tasks.
“The .xyz section [is] LZMA compressed - SnappyClient” and “.data [is] LZMA compressed - Module table.”
“The same API resolution order” and “a fresh copy of ntdll.dll is mapped from disk and a second batch of functions is resolved from it.”
Its author has teased plans to inject code into Electron-based apps, including the Ledger and Trezor wallet managers.
“The loader marks its own image writable, zeroes it and then calls into the function that is responsible for mapping the final payload in its place. From this point on the process is executing out of memory it has just erased.”
“Both are decompressed by the same function” and the loader “decompresses two sections.”
From there, they can launch stealers, log keystrokes, watch the clipboard, or push more payloads.
The malware leans on session hijacking, too. As Group-IB explains, seizing an active session can bypass passwords and even multi-factor authentication.
From there, they can launch stealers, log keystrokes, watch the clipboard, or push more payloads.
Subsequently, SnappyClient sends an encrypted packet with the message header, followed by another packet containing the encrypted and compressed message.
The malware communicates with its C&C server using a custom binary protocol. The traffic is encrypted with ChaCha20-Poly1305 using a key and nonce received from the server, which are exchanged and validated before any control commands are sent or received.
The malware communicates with its C&C server using a custom binary protocol.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Final payload delivered by HijackLoader, either directly or through an intermediary 32-bit self-hollowing loader that decompresses and maps it into memory.
A remote access trojan designed to provide persistent access to compromised environments.
A stealthy RAT delivered in the campaign's second parallel infection chain. It is unpacked by a second HijackLoader path, hollowed into a legitimate host process, communicates with C2 over ports 3333/3334, and establishes persistence via a Startup shortcut and scheduled task.
Mentioned only as a C2 implant targeting crypto wallets; no further details are provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.