{"id":11456,"date":"2026-03-19T10:03:38","date_gmt":"2026-03-19T10:03:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/19\/new-snappyclient-implant-combines-remote-access-data-theft-and-advanced-evasion\/"},"modified":"2026-03-19T10:03:38","modified_gmt":"2026-03-19T10:03:38","slug":"new-snappyclient-implant-combines-remote-access-data-theft-and-advanced-evasion","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/19\/new-snappyclient-implant-combines-remote-access-data-theft-and-advanced-evasion\/","title":{"rendered":"New SnappyClient Implant Combines Remote Access, Data Theft and Advanced Evasion"},"content":{"rendered":"<p>    New SnappyClient Implant Combines Remote Access, Data Theft and Advanced Evasion<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A dangerous new malware implant called SnappyClient has quietly emerged as a serious threat to Windows users, combining remote access, data theft, and sophisticated evasion techniques in one compact C++ package. <\/p>\n<p>First spotted in December 2025, this command-and-control (C2) framework implant can log keystrokes, take screenshots, launch a remote terminal, and pull sensitive data from browsers and applications \u2014 all while avoiding detection by <a href=\"https:\/\/cybersecuritynews.com\/best-cloud-security-tools\/\" id=\"11635\" target=\"_blank\" rel=\"noreferrer noopener\">security tools<\/a>.<\/p>\n<p>The attack chain begins with a convincingly fake website impersonating Telef\u00f3nica, the well-known telecommunications company. German-speaking users who visit the page are automatically served a HijackLoader download. <\/p>\n<p>Once the victim runs the file, HijackLoader decrypts and loads SnappyClient directly into memory. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjkMFOmt6RaBq4nKqFeQkZ6i7NUdc-H9OrNjKWzBoSWQjNDLIMbRTSm_AEy4GM-d-41Gr5yYfABhPgRkt0SEFv71oof60SlkkRzBnr44Pc4KdCGe9xymOMcA01x545dE2TfrwwTLH2OnhwNIPphCD8lX_bf_GvetnEhl5nkSdpbfPki5RSwc5kuXJYaDoY\/s16000\/Attack%2520chain%2520%28Source%2520-%2520Zscaler%29.webp?ssl=1\" alt=\"Attack chain (Source - Zscaler)\"><figcaption class=\"wp-element-caption\">Attack chain (Source \u2013 Zscaler)<\/figcaption><\/figure>\n<\/div>\n<p>A second delivery method was also observed in early February 2026, where attackers used a ClickFix trick shared via X (formerly Twitter), again dropping SnappyClient through GhostPulse and HijackLoader.<\/p>\n<p><a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/technical-analysis-snappyclient\" id=\"https:\/\/www.zscaler.com\/blogs\/security-research\/technical-analysis-snappyclient\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Zscaler ThreatLabz researchers identified SnappyClient<\/a> in December 2025 while tracking HijackLoader activity across their telemetry. Their analysis revealed that SnappyClient communicates with its C2 server over TCP using a fully custom protocol. <\/p>\n<p>Every message is compressed with the Snappy algorithm and encrypted using ChaCha20-Poly1305, making network traffic significantly harder for defenders to inspect.<\/p>\n<p>SnappyClient targets a wide range of applications for data theft. It goes after ten browsers including Chrome, Firefox, Edge, Opera, and Brave, harvesting saved passwords, session cookies, and full browser profiles. <\/p>\n<p>The malware also hunts for cryptocurrency-related extensions such as MetaMask, Phantom, TronLink, Coinbase Wallet, and TrustWallet. Standalone <a href=\"https:\/\/cybersecuritynews.com\/what-drives-crypto-prices-key-factors-behind-market-fluctuations\/\" id=\"116858\" target=\"_blank\" rel=\"noreferrer noopener\">crypto applications<\/a> including Exodus, Atomic, Electrum, and Ledger Live are targeted as well. <\/p>\n<p>Network analysis confirmed that cryptocurrency theft is the primary financial goal driving these campaigns.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjEgUkGavBsqFrk8_Q-O98uzJyeHMzEKgPLCjoDUsXa9BTWH5R537OZAN2N8ZfgWPjPzwjb9RGekxAw6QNKRo2bHO3hL53I4wCaIUw2saVV6sBNtIs4SVOmazZSPEuE6xCKCdDCGQz50Lb8eAVPhk6MqDejXMzm-mfAAu4JmAnX1t2720o-xaGNmkzjg0s\/s16000\/Fake%2520Telef%25C3%25B3nica%2520Website%2520Delivering%2520HijackLoader%2520%28Source%2520-%2520Zscaler%29.webp?ssl=1\" alt=\"Fake Telef\u00f3nica Website Delivering HijackLoader (Source - Zscaler)\"><figcaption class=\"wp-element-caption\">Fake Telef\u00f3nica Website Delivering HijackLoader (Source \u2013 Zscaler)<\/figcaption><\/figure>\n<\/div>\n<p>Beyond stealing data, SnappyClient supports reverse proxies for FTP, VNC, SOCKS5, and RLOGIN, giving attackers multiple pathways inside a victim\u2019s network. <\/p>\n<p>It monitors clipboard content in real time, silently swapping out Ethereum wallet addresses to redirect <a href=\"https:\/\/cybersecuritynews.com\/crypto-in-everyday-transactions\/\" id=\"87419\" target=\"_blank\" rel=\"noreferrer noopener\">crypto transactions<\/a>. <\/p>\n<p>Two dynamic configuration files \u2014 EventsDB and SoftwareDB \u2014 are pushed by the C2 server to direct the implant on which applications to target and what actions to take, making it flexible without requiring redeployment.<\/p>\n<h2 class=\"wp-block-heading\" id=\"inside-snappyclients-evasion-and-persistence\"><strong>Inside SnappyClient\u2019s Evasion and Persistence<\/strong><\/h2>\n<p>What makes SnappyClient hard to stop is how efficiently it dismantles the security controls meant to catch it. From the moment it starts, the implant hooks Windows\u2019\u00a0<code>LoadLibraryExW<\/code>\u00a0function and monitors for any attempt to load\u00a0<code>amsi.dll<\/code>. <\/p>\n<p>When detected, it patches\u00a0<code>AmsiScanBuffer<\/code>\u00a0and\u00a0<code>AmsiScanString<\/code>\u00a0to always return a clean result, silently disabling Windows\u2019 Antimalware Scan Interface without raising any alerts.<\/p>\n<p>To bypass user-mode API hooks placed by endpoint security products, SnappyClient uses Heaven\u2019s Gate, switching execution between 32-bit and 64-bit modes to issue direct system calls that skip the monitored API layers. <\/p>\n<p>It also maps a clean copy of\u00a0<code>ntdll.dll<\/code>\u00a0into memory, accessing core Windows functions without interference. These patterns closely mirror HijackLoader\u2019s design, pointing to a likely connection between the developers of both tools.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgJZ-ayyJ8tlBTAgo3Lns1dnp_ouE_HpdXxBDhn6nLpLafQpWgEnnqc5PFaM7vB8Q5aZC1RtWK3rW9MhNhoeHBoB7x7ORuUyK2iZPInYIvUE9Mb745syxglN7RhQVthNBf_96DI7sdsJRKI4czSo1rKIIxMQHhpBMWAuUjXvmGpnX0yyGqsjptM2lo9PSM\/s16000\/API%2520structure%2520layout%2520of%2520HijackLoader%2520and%2520SnappyClient%2520%28Source%2520-%2520Zscaler%29.webp?ssl=1\" alt=\"API structure layout of HijackLoader and SnappyClient (Source - Zscaler)\"><figcaption class=\"wp-element-caption\">API structure layout of HijackLoader and SnappyClient (Source \u2013 Zscaler)<\/figcaption><\/figure>\n<\/div>\n<p>For persistence, SnappyClient first registers a scheduled task that fires at every user logon. If that fails, it writes an autorun entry under\u00a0<code>SoftwareMicrosoftWindowsCurrentVersionRun<\/code>. <\/p>\n<p>The implant copies itself to a configured path and launches from there, terminating the original process. <\/p>\n<p>All sensitive files stored on disk \u2014 including the keylogger file, EventsDB, and SoftwareDB \u2014 are encrypted with ChaCha20, making forensic recovery considerably harder.<\/p>\n<p>Users and organizations should avoid downloading executable files from unverified websites, even those appearing to represent known brands. <\/p>\n<p>Security teams should monitor for unusual scheduled task creation and suspicious registry run key changes, as early warning signs of SnappyClient\u2019s persistence routine. <\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/real-time-endpoint-threat-detection\/\" id=\"107414\" target=\"_blank\" rel=\"noreferrer noopener\">Endpoint detection<\/a> rules should cover Heaven\u2019s Gate execution patterns and transacted hollowing behavior. Keeping browsers updated lowers the risk of App-Bound Encryption bypass. Regularly auditing installed browser extensions \u2014 especially those linked to cryptocurrency wallets \u2014 is strongly recommended.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-snappyclient-implant-combines\/\">New SnappyClient Implant Combines Remote Access, Data Theft and Advanced Evasion<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-snappyclient-implant-combines\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New SnappyClient Implant Combines Remote Access, Data Theft and Advanced Evasion A dangerous new malware implant called SnappyClient has quietly emerged as a serious threat to Windows users, combining remote access, data theft, and sophisticated evasion techniques in one compact C++ package. First spotted in December 2025, this command-and-control (C2) framework implant can log keystrokes, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-11456","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11456"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11456"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11456\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11456"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11456"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11456"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}