Applications of Snake Keylogger in Geopolitics: Abuse of Trusted Java Utilities in Cybercriminal Activities

July 13, 2025, 9:36 a.m.

Description

A new phishing campaign using Snake Keylogger, a Russian-origin stealer, has been discovered targeting various victims including corporations, governments, and individuals. The campaign uses spear-phishing emails offering petroleum products, with malicious attachments exploiting the legitimate jsadebugd.exe binary through DLL sideloading to load Snake Keylogger. The attackers are leveraging current geopolitical tensions in the Middle East to expand their reach. The malware steals credentials from browsers and applications, collects system information, and exfiltrates data via SMTP. This campaign marks the first observed malicious use of jsadebugd.exe, indicating evolving tactics to evade detection.

Date

  • Created: July 6, 2025, 11:54 a.m.
  • Published: July 6, 2025, 11:54 a.m.
  • Modified: July 13, 2025, 9:36 a.m.

Attack Patterns

Additional Informations

  • Energy
  • Iran, Islamic Republic of
  • Kazakhstan
  • Israel
  • United States of America