SnakeKeylogger: Multistage Info Stealer Malware Analysis & Prevention
March 25, 2025, 1:19 p.m.
Description
SnakeKeylogger is a highly active credential-stealing malware targeting individuals and businesses. It employs a multi-stage infection chain, starting with malicious spam emails containing .img files. The malware uses sophisticated techniques like process hollowing and obfuscation to evade detection. It targets various applications, including web browsers, email clients, and FTP software, to harvest sensitive data and credentials. The campaign utilizes an Apache server for malware distribution, regularly updating encrypted payloads. SnakeKeylogger's primary objective is to collect Outlook profile credentials, email configurations, and stored authentication details, which can be exploited for business email compromise or sold on underground markets.
Tags
Date
- Created: March 25, 2025, 10:46 a.m.
- Published: March 25, 2025, 10:46 a.m.
- Modified: March 25, 2025, 1:19 p.m.
Indicators
- 7a5a195be41d691882da0610b142ab0f82b6cccfa5b66db38b5a2416f5e4b62d
- 103.72.56.30