Skip to content

SnakeKeylogger

SnakeKeylogger, also known as 404 Keylogger and in some campaigns rebranded as VIPKeylogger, is a Windows-focused .NET credential-stealing malware family active since at least late 2020.

Profile source: Mallory opens in a new tab

SnakeKeylogger

Family profile

SnakeKeylogger, also known as 404 Keylogger and in some campaigns rebranded as VIPKeylogger, is a Windows-focused .NET credential-stealing malware family active since at least late 2020. It overlaps functionally with commodity stealers such as Agent Tesla and is used primarily for theft of credentials and other sensitive user data from compromised endpoints.

The malware is associated with phishing-led intrusion chains that commonly use business or logistics lures, including proposal, purchase-order, invoice, and DHL-themed messages. Observed delivery mechanisms include malicious JavaScript, VBScript, PowerShell, and macro-enabled Microsoft Word documents. Several campaigns used staged loaders that decrypt SnakeKeylogger in memory, reflective .NET loading, abuse of legitimate Windows components, and process hollowing into trusted .NET binaries to reduce on-disk artifacts and evade detection. Some variants have also been delivered through broader malware distribution ecosystems and loaders.

SnakeKeylogger’s core behavior includes keylogging, theft of browser-stored data, collection of system information, and credential harvesting. Reported variants target credentials and data from numerous Chromium- and Gecko-based browsers as well as email and file-transfer clients. Additional observed collection includes clipboard contents, screenshots, Wi-Fi credentials, Discord-related data, and other locally stored secrets. Exfiltration has been observed over SMTP and Telegram, and some later variants also support HTTP POST, FTP, and Discord webhooks. VIPKeylogger-branded samples have been described as using dual-channel exfiltration, particularly SMTP and Telegram simultaneously.

The family is frequently protected with obfuscation and encrypted configuration or payload stages, including custom XOR-based loaders and, in some reported variants, RSA and AES for configuration and communications. Campaigns have also shown anti-analysis measures, persistence via scheduled tasks or startup mechanisms, and use of social engineering combined with trusted-process abuse. SnakeKeylogger remains effective because it combines simple credential-theft objectives with low-cost delivery and broad compatibility across poorly secured Windows endpoints.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 27, 2026
Last activity
Jul 27, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • DE1

Leading providers

  • Hetzner Online GmbH1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

SnakeKeylogger in ATT&CK

45 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.