216.73.217.22

Technical Analysis of SnappyClient

· Published 18/03/2026 15:30 · Modified 18/03/2026 16:51

Export JSON

Essential information

Published
18/03/2026 15:30
Modified
18/03/2026 16:51
Tags
2026-03-18 command and control cryptocurrency data theft evasion hijackloader remote access snappyclient
Related entities
5 observables, 19 techniques (mitre), 2 malware, 2 others

Description

Zscaler ThreatLabz identified a new command-and-control framework implant called , delivered via . is a C++-based implant with and capabilities. It employs techniques like AMSI bypass, Heaven's Gate, direct system calls, and transacted hollowing. The malware receives configuration files from its C2 server and uses a custom encrypted network protocol. 's main functions include stealing browser data, taking screenshots, keylogging, and providing remote shell access. Analysis suggests potential ties to based on code similarities. The primary goal appears to be theft, targeting wallet addresses and crypto-related applications.

External references