SnappyClient is a Windows-focused C++ command-and-control implant and remote access trojan first observed in late 2025. It is designed for stealthy persistence, long-term post-compromise access, surveillance, and data theft, with observed operations strongly associated with financially motivated cryptocurrency theft. The malware has been described both as a C2 framework and as a RAT because it combines operator-controlled remote access with modular theft and post-exploitation functions.
SnappyClient has been observed delivered via HijackLoader and in campaigns using fake software-update lures, spoofed telecommunications-themed download pages, spearphishing, and ClickFix-style social engineering chains. In one documented intrusion set, it was deployed through DLL sideloading using signed applications as cover, with HijackLoader unpacking and launching the final implant.
The malware supports persistence through scheduled tasks and Windows autorun mechanisms. It includes multiple defense-evasion features, including AMSI bypass through hooking, direct system calls, 64-bit execution techniques such as Heaven’s Gate, process injection, and tradecraft intended to reduce visibility to user-mode security tooling. It also supports single-instance control and can maintain encrypted local configuration and tasking data.
SnappyClient communicates with its command-and-control infrastructure over a custom TCP binary protocol. Traffic is compressed and encrypted, with reporting and tasking protected using ChaCha20-Poly1305. After registration, the implant can receive updated configuration and dynamically targeted theft instructions from the operator.
Its capability set is extensive. SnappyClient can capture screenshots, log keystrokes, execute files, provide remote shell access, browse files and directories, manage processes, and exfiltrate stolen information. It can steal credentials, cookies, browser profile data, browser extension data, and information from other applications. Reported targeting includes major Chromium- and Gecko-based browsers, cryptocurrency wallet extensions, and desktop wallet applications. It has also been observed using techniques to obtain Chromium encryption material and bypass App-Bound Encryption protections, enabling theft of protected browser secrets. Additional functionality includes reverse proxy services for operator access, including hidden remote desktop and proxy-style channels.
Observed tasking and target selection indicate a strong focus on cryptocurrency-related activity, including wallet data theft and monitoring for crypto-related user behavior. SnappyClient has also been linked to campaigns affecting financial organizations. Code and tradecraft overlaps with HijackLoader have been reported, suggesting a possible developer or operational relationship between the two malware families.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Victims usually meet a ClickFix prompt through phishing, malicious ads, or compromised websites.
Group-IB observed SilabRAT spreading through email spam and ClickFix social engineering. Victims usually meet a ClickFix prompt through phishing, malicious ads, or compromised websites.
It can also escalate privileges through a known UAC bypass and set up persistence via registry keys or scheduled tasks.
a user was tricked into running a malicious PowerShell command
The Blackpoint SOC received alerts for suspicious powershell.exe usage by a user who fell for a ClickFix-style (Win+R) attack.
Attackers can use the implant to establish a remote shell on compromised systems for direct command-line access.
It can also escalate privileges through a known UAC bypass and set up persistence via registry keys or scheduled tasks.
It can also escalate privileges through a known UAC bypass and set up persistence via registry keys or scheduled tasks.
Its author has teased plans to inject code into Electron-based apps, including the Ledger and Trezor wallet managers.
Vidar is decrypted in memory and injected, through process hollowing, into a clean, signed third-party application
It can also escalate privileges through a known UAC bypass and set up persistence via registry keys or scheduled tasks.
To bypass Chromium’s App-Bound Encryption... SnappyClient uses transacted hollowing... to inject a payload, which retrieves Chromium's AES_256 master key.
This is a standard way to keep recognizable strings like CreateFileW or VirtualProtect out of the binary
Its author has teased plans to inject code into Electron-based apps, including the Ledger and Trezor wallet managers.
From there, they can launch stealers, log keystrokes, watch the clipboard, or push more payloads.
The malware leans on session hijacking, too. As Group-IB explains, seizing an active session can bypass passwords and even multi-factor authentication.
From there, they can launch stealers, log keystrokes, watch the clipboard, or push more payloads.
Subsequently, SnappyClient sends an encrypted packet with the message header, followed by another packet containing the encrypted and compressed message.
The malware communicates with its C&C server using a custom binary protocol. The traffic is encrypted with ChaCha20-Poly1305 using a key and nonce received from the server, which are exchanged and validated before any control commands are sent or received.
Set up a reverse FTP proxy... reverse VNC proxy... reverse RLOGIN proxy... reverse SOCKS5 proxy... enabling the C2 to relay traffic through the victim machine.
The malware communicates with its C&C server using a custom binary protocol.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan designed to provide persistent access to compromised environments.
A stealthy RAT delivered in the campaign's second parallel infection chain. It is unpacked by a second HijackLoader path, hollowed into a legitimate host process, communicates with C2 over ports 3333/3334, and establishes persistence via a Startup shortcut and scheduled task.
A command-and-control implant used for crypto wallet targeting.
Mentioned only as a C2 implant targeting crypto wallets; no further details are provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.