Last seven days
- First activity
- Aug 11, 2026
- Last activity
- Aug 12, 2026
- Feed role
- C2
- Host form
- 2 IP / 1 hostnames
SnappyClient is a Windows-focused C++ command-and-control implant and remote access trojan first observed in late 2025.
Profile source: Mallory opens in a new tabSnappyClient
SnappyClient is a Windows-focused C++ command-and-control implant and remote access trojan first observed in late 2025. It is designed for stealthy persistence, long-term post-compromise access, surveillance, and data theft, with observed operations strongly associated with financially motivated cryptocurrency theft. The malware has been described both as a C2 framework and as a RAT because it combines operator-controlled remote access with modular theft and post-exploitation functions.
SnappyClient has been observed delivered via HijackLoader and in campaigns using fake software-update lures, spoofed telecommunications-themed download pages, spearphishing, and ClickFix-style social engineering chains. In one documented intrusion set, it was deployed through DLL sideloading using signed applications as cover, with HijackLoader unpacking and launching the final implant.
The malware supports persistence through scheduled tasks and Windows autorun mechanisms. It includes multiple defense-evasion features, including AMSI bypass through hooking, direct system calls, 64-bit execution techniques such as Heaven’s Gate, process injection, and tradecraft intended to reduce visibility to user-mode security tooling. It also supports single-instance control and can maintain encrypted local configuration and tasking data.
SnappyClient communicates with its command-and-control infrastructure over a custom TCP binary protocol. Traffic is compressed and encrypted, with reporting and tasking protected using ChaCha20-Poly1305. After registration, the implant can receive updated configuration and dynamically targeted theft instructions from the operator.
Its capability set is extensive. SnappyClient can capture screenshots, log keystrokes, execute files, provide remote shell access, browse files and directories, manage processes, and exfiltrate stolen information. It can steal credentials, cookies, browser profile data, browser extension data, and information from other applications. Reported targeting includes major Chromium- and Gecko-based browsers, cryptocurrency wallet extensions, and desktop wallet applications. It has also been observed using techniques to obtain Chromium encryption material and bypass App-Bound Encryption protections, enabling theft of protected browser secrets. Additional functionality includes reverse proxy services for operator access, including hidden remote desktop and proxy-style channels.
Observed tasking and target selection indicate a strong focus on cryptocurrency-related activity, including wallet data theft and monitoring for crypto-related user behavior. SnappyClient has also been linked to campaigns affecting financial organizations. Code and tradecraft overlaps with HijackLoader have been reported, suggesting a possible developer or operational relationship between the two malware families.
C2 tracking
Derp observations, rolling seven-day window
Samples
3009da6315caea9fb18c11e5a74e2c466245510dbb55e9a87668fb9a50abd0ca 7123e1514b939b165985560057fe3c761440a9fff9783a3b84e861fd2888d4ab 7ea2078158ff32452de41964f7eb4014a291182024c9126341a0690d2271b832 9993b81fa94e2a2897179d38c9d0610b2c4d3af7aea4f41cbe31a286050fd9be afddbebc3e0de2f6d25a3ed419153941cabfadb8480697bc32632a2f61630e65 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.