Skip to content

MatIEx

Matiex is a Windows-based .NET keylogger and information-stealing malware sold on underground forums as a commodity malware offering.

Profile source: Mallory opens in a new tab

MatIEx

Family profile

Matiex is a Windows-based .NET keylogger and information-stealing malware sold on underground forums as a commodity malware offering. It has been marketed with multiple operator-friendly features, including configurable installation behavior, startup persistence, self-removal, and several exfiltration options. The malware is associated with the broader ecosystem of commodity .NET stealers and keyloggers, and multiple analyses have noted strong code and architectural similarities between Matiex and Snake Keylogger, with some reporting that Snake likely shares a common code base or may have evolved from Matiex. Matiex has also appeared as a payload in phishing-delivered malware campaigns alongside other commodity stealers such as Agent Tesla, FormBook, Azorult, and njRat.

Matiex is designed primarily for surveillance and theft of user data. Reported capabilities include Unicode keystroke logging, clipboard capture, screenshot collection, microphone recording, password and sensitive-data theft from more than 60 browsers, victim IP discovery, and remote upload of stolen information. Exfiltration channels advertised or observed for Matiex include FTP, SMTP or email, Telegram, Discord, and in some reporting HTTP. The malware also supports persistence on Windows through startup mechanisms and includes a self-destruction feature intended to remove the malware after an operation is complete. Some reporting indicates support for binder-style execution, allowing the malware to be packaged with other files so it runs when those files are opened.

Observed delivery has included spam email carrying malicious attachments, including archive files masquerading as legitimate content. Matiex has also been identified as a final payload in broader phishing campaigns using malicious Office documents and staged droppers. Its packaging, sales model, and support structure are consistent with malware-as-a-service commercialization aimed at a wide range of criminal operators rather than a narrowly targeted intrusion set.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 8, 2026
Last activity
Sep 10, 2026
Feed role
C2
Host form
0 IP / 2 hostnames

Leading locations

  • US1

Samples

Recent associated samples

MITRE ATT&CK

MatIEx in ATT&CK

21 distinct techniques

Reporting

Research mentioning MatIEx

Jan 1
Cybereason

THREAT ANALYSIS REPORT: Snake Infostealer Malware

Researchers detailed ongoing Snake Keylogger activity in which attackers deliver the .NET-based infostealer through phishing emails carrying archive files, malicious executables, exploit-laden RTF documents abusing CVE-2017-11882, and Excel attachments with password-protected VBA macros. In one analyzed chain, a lure such as SeptemberOrderlist.pdf.exe decrypted intermediate .NET assemblies before launching the final payload, while another used base64-encoded PowerShell to download a Snake downloader, retrieve an RC4-encrypted DLL, and deploy the malware through process hollowing. Snake is designed to steal credentials and other sensitive data from more than 50 applications, including browsers, email and FTP clients, communication tools, wireless profiles, and Windows product information, while also capturing keystrokes, screenshots, clipboard contents, host details, geolocation, and time data. The malware can persist through scheduled tasks or Startup-folder registry changes, evade defenses by killing security tools, adding Windows Defender exclusions, and deleting itself, and exfiltrate stolen data over SMTP, FTP, or Telegram via HTTPS. Multiple researchers said Snake shares strong code and loader similarities with commodity stealers such as FormBook, Agent Tesla, Matiex, 404, Cheetah, and Phoenix, pointing to code reuse or shared tooling in the cybercrime ecosystem.

Nov 4
Fortinet Threat Research

Deep Dive into a Fresh Variant of Snake Keylogger Malware | FortiGuard Labs

Jun 28
Hp Wolf Threat Research

Snake Keylogger's Many Skins: Analysing Code Reuse Among Infostealers | HP Wolf Security

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.