Last seven days
- First activity
- Sep 8, 2026
- Last activity
- Sep 10, 2026
- Feed role
- C2
- Host form
- 0 IP / 2 hostnames
Matiex is a Windows-based .NET keylogger and information-stealing malware sold on underground forums as a commodity malware offering.
Profile source: Mallory opens in a new tabMatIEx
Matiex is a Windows-based .NET keylogger and information-stealing malware sold on underground forums as a commodity malware offering. It has been marketed with multiple operator-friendly features, including configurable installation behavior, startup persistence, self-removal, and several exfiltration options. The malware is associated with the broader ecosystem of commodity .NET stealers and keyloggers, and multiple analyses have noted strong code and architectural similarities between Matiex and Snake Keylogger, with some reporting that Snake likely shares a common code base or may have evolved from Matiex. Matiex has also appeared as a payload in phishing-delivered malware campaigns alongside other commodity stealers such as Agent Tesla, FormBook, Azorult, and njRat.
Matiex is designed primarily for surveillance and theft of user data. Reported capabilities include Unicode keystroke logging, clipboard capture, screenshot collection, microphone recording, password and sensitive-data theft from more than 60 browsers, victim IP discovery, and remote upload of stolen information. Exfiltration channels advertised or observed for Matiex include FTP, SMTP or email, Telegram, Discord, and in some reporting HTTP. The malware also supports persistence on Windows through startup mechanisms and includes a self-destruction feature intended to remove the malware after an operation is complete. Some reporting indicates support for binder-style execution, allowing the malware to be packaged with other files so it runs when those files are opened.
Observed delivery has included spam email carrying malicious attachments, including archive files masquerading as legitimate content. Matiex has also been identified as a final payload in broader phishing campaigns using malicious Office documents and staged droppers. Its packaging, sales model, and support structure are consistent with malware-as-a-service commercialization aimed at a wide range of criminal operators rather than a narrowly targeted intrusion set.
C2 tracking
Derp observations, rolling seven-day window
Samples
5ed1ca31300cdef81d6bbbba39924b2a6b163d49a124f6f0a3bc997b122aba62 06b010ca61dc0f60112862489c2a00b9428997518a7eca80d6a3cb72aef20276 3adbc03b0ad4bec21bf84a37e4335f4d515f567206d6390a0300687b099b31d3 94918a637acd574b9a0d4acf4bbe55a3ca5c864fd3f537ab6fcebbf25ce7d063 aedfd8af5487ff9fbf3d97d57b7fe77353e09e3d07a4803de4d6f90f1c5af082 ffb578d1969390c35676b32dd53b6fbbe29c0940fdf511377284efe3c80f6181 MITRE ATT&CK
Reporting
Researchers detailed ongoing Snake Keylogger activity in which attackers deliver the .NET-based infostealer through phishing emails carrying archive files, malicious executables, exploit-laden RTF documents abusing CVE-2017-11882, and Excel attachments with password-protected VBA macros. In one analyzed chain, a lure such as SeptemberOrderlist.pdf.exe decrypted intermediate .NET assemblies before launching the final payload, while another used base64-encoded PowerShell to download a Snake downloader, retrieve an RC4-encrypted DLL, and deploy the malware through process hollowing. Snake is designed to steal credentials and other sensitive data from more than 50 applications, including browsers, email and FTP clients, communication tools, wireless profiles, and Windows product information, while also capturing keystrokes, screenshots, clipboard contents, host details, geolocation, and time data. The malware can persist through scheduled tasks or Startup-folder registry changes, evade defenses by killing security tools, adding Windows Defender exclusions, and deleting itself, and exfiltrate stolen data over SMTP, FTP, or Telegram via HTTPS. Multiple researchers said Snake shares strong code and loader similarities with commodity stealers such as FormBook, Agent Tesla, Matiex, 404, Cheetah, and Phoenix, pointing to code reuse or shared tooling in the cybercrime ecosystem.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.