Skip to content

SnakeKeylogger

SnakeKeylogger, also known as 404 Keylogger, is a .NET-based Windows information stealer active since at least late 2020.

Profile source: Mallory opens in a new tab

SnakeKeylogger

Family profile

SnakeKeylogger, also known as 404 Keylogger, is a .NET-based Windows information stealer active since at least late 2020. It steals browser-stored data and system information and includes keylogging functionality. Recent versions have targeted credentials and other data from Chromium- and Gecko-based browsers, email and FTP clients, Discord tokens, payment-card data, Wi-Fi passwords, clipboard contents, and screenshots. The malware has used SMTP and Telegram for data exfiltration, with some variants supporting HTTP, FTP, and Discord webhooks. VIPKeylogger is widely described as a direct variant or rebrand of SnakeKeylogger.

SnakeKeylogger is commonly delivered through phishing emails using business, shipping, project-proposal, purchase-order, invoice, and DHL-themed lures. Observed delivery chains employ malicious Microsoft Office documents with macros, JavaScript, VBScript, and PowerShell downloaders. Operators use obfuscation, encrypted payloads, reflective in-memory loading, legitimate Windows utilities, anti-analysis checks, and process hollowing to evade detection. Persistence has been observed through scheduled tasks and startup execution. SnakeKeylogger has also been distributed by the PureCrypter malware-as-a-service loader. No specific threat actor attribution is established.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 8, 2026
Last activity
Sep 9, 2026
Feed role
C2
Host form
1 IP / 1 hostnames

Leading locations

  • MY1
  • US1

Leading providers

  • DEFT.COM1
  • SKSA TECHNOLOGY SDN BHD1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

MITRE ATT&CK

SnakeKeylogger in ATT&CK

46 distinct techniques

Reporting

Research mentioning SnakeKeylogger

Mar 6
Malpedia

404 Keylogger (Malware Family)

Elastic added behavioral Windows keylogger detection to Elastic Defend 8.12, using Event Tracing for Windows (ETW) to observe API activity associated with keystroke collection through polling, keyboard hooks, Raw Input, and DirectInput. Prebuilt endpoint rules identify suspicious use of APIs including GetAsyncKeyState, SetWindowsHookEx, and RegisterRawInputDevices. In testing on Windows 10, Elastic Defend detected a proof-of-concept Raw Input keylogger soon after it executed, flagging an untrusted process that registered for keyboard input. The telemetry captures API arguments, call-stack context, process-signature status, and related process metadata, enabling defenders to investigate credential- and information-theft activity while reducing false positives from legitimate accessibility and input software.

Oct 16
Bitsight

Exfiltration over Telegram Bots: Skidding Infostealer Logs | Bitsight

Researchers reported that Telegram has become a major channel for infostealer operators to exfiltrate stolen data and distribute victim logs, exposing a large volume of corporate credentials and access data. BitSight said analysis of roughly 1,800 Telegram bots collected from October 2024 onward uncovered about 5 million logs, 2.8 million credentials, more than 400,000 unique domains, and over 10,000 unique IP addresses, with credentials linked to nearly 60,000 organizations. The activity reflects a broader Russian-speaking infostealer ecosystem in which harvested logs are packaged, shared, and monetized for follow-on intrusion activity. The most prominent malware families observed were SnakeKeylogger and AgentTesla, with SnakeKeylogger rising sharply and VipKeylogger appearing as a SnakeKeylogger variant, while AgentTesla/OriginLogger activity declined after operators reportedly lost access to servers and backups. Infections were globally distributed, led by the United States, Turkey, and Russia, followed by India and Germany. The findings underscore that stolen credentials remain a key initial-access vector, prompting recommendations to block api.telegram.org where not required, enforce MFA, and monitor for leaked credentials tied to enterprise accounts.

May 30
Elastic Security Labs

Protecting your devices from information theft | Elastic Security Labs

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.