Last seven days
- First activity
- Sep 8, 2026
- Last activity
- Sep 9, 2026
- Feed role
- C2
- Host form
- 1 IP / 1 hostnames
SnakeKeylogger, also known as 404 Keylogger, is a .NET-based Windows information stealer active since at least late 2020.
Profile source: Mallory opens in a new tabSnakeKeylogger
SnakeKeylogger, also known as 404 Keylogger, is a .NET-based Windows information stealer active since at least late 2020. It steals browser-stored data and system information and includes keylogging functionality. Recent versions have targeted credentials and other data from Chromium- and Gecko-based browsers, email and FTP clients, Discord tokens, payment-card data, Wi-Fi passwords, clipboard contents, and screenshots. The malware has used SMTP and Telegram for data exfiltration, with some variants supporting HTTP, FTP, and Discord webhooks. VIPKeylogger is widely described as a direct variant or rebrand of SnakeKeylogger.
SnakeKeylogger is commonly delivered through phishing emails using business, shipping, project-proposal, purchase-order, invoice, and DHL-themed lures. Observed delivery chains employ malicious Microsoft Office documents with macros, JavaScript, VBScript, and PowerShell downloaders. Operators use obfuscation, encrypted payloads, reflective in-memory loading, legitimate Windows utilities, anti-analysis checks, and process hollowing to evade detection. Persistence has been observed through scheduled tasks and startup execution. SnakeKeylogger has also been distributed by the PureCrypter malware-as-a-service loader. No specific threat actor attribution is established.
C2 tracking
Derp observations, rolling seven-day window
Samples
MITRE ATT&CK
Reporting
Elastic added behavioral Windows keylogger detection to Elastic Defend 8.12, using Event Tracing for Windows (ETW) to observe API activity associated with keystroke collection through polling, keyboard hooks, Raw Input, and DirectInput. Prebuilt endpoint rules identify suspicious use of APIs including GetAsyncKeyState, SetWindowsHookEx, and RegisterRawInputDevices. In testing on Windows 10, Elastic Defend detected a proof-of-concept Raw Input keylogger soon after it executed, flagging an untrusted process that registered for keyboard input. The telemetry captures API arguments, call-stack context, process-signature status, and related process metadata, enabling defenders to investigate credential- and information-theft activity while reducing false positives from legitimate accessibility and input software.
Researchers reported that Telegram has become a major channel for infostealer operators to exfiltrate stolen data and distribute victim logs, exposing a large volume of corporate credentials and access data. BitSight said analysis of roughly 1,800 Telegram bots collected from October 2024 onward uncovered about 5 million logs, 2.8 million credentials, more than 400,000 unique domains, and over 10,000 unique IP addresses, with credentials linked to nearly 60,000 organizations. The activity reflects a broader Russian-speaking infostealer ecosystem in which harvested logs are packaged, shared, and monetized for follow-on intrusion activity. The most prominent malware families observed were SnakeKeylogger and AgentTesla, with SnakeKeylogger rising sharply and VipKeylogger appearing as a SnakeKeylogger variant, while AgentTesla/OriginLogger activity declined after operators reportedly lost access to servers and backups. Infections were globally distributed, led by the United States, Turkey, and Russia, followed by India and Germany. The findings underscore that stolen credentials remain a key initial-access vector, prompting recommendations to block api.telegram.org where not required, enforce MFA, and monitor for leaked credentials tied to enterprise accounts.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.