Last seven days
- First activity
- Aug 2, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 2 IP / 1 hostnames
SnappyClient is a Windows-focused C++ command-and-control implant and remote access trojan first observed in late 2025.
Profile source: Mallory opens in a new tabSnappyClient
SnappyClient is a Windows-focused C++ command-and-control implant and remote access trojan first observed in late 2025. It is designed for stealthy persistence, long-term post-compromise access, surveillance, and data theft, with observed operations strongly associated with financially motivated cryptocurrency theft. The malware has been described both as a C2 framework and as a RAT because it combines operator-controlled remote access with modular theft and post-exploitation functions.
SnappyClient has been observed delivered via HijackLoader and in campaigns using fake software-update lures, spoofed telecommunications-themed download pages, spearphishing, and ClickFix-style social engineering chains. In one documented intrusion set, it was deployed through DLL sideloading using signed applications as cover, with HijackLoader unpacking and launching the final implant.
The malware supports persistence through scheduled tasks and Windows autorun mechanisms. It includes multiple defense-evasion features, including AMSI bypass through hooking, direct system calls, 64-bit execution techniques such as Heaven’s Gate, process injection, and tradecraft intended to reduce visibility to user-mode security tooling. It also supports single-instance control and can maintain encrypted local configuration and tasking data.
SnappyClient communicates with its command-and-control infrastructure over a custom TCP binary protocol. Traffic is compressed and encrypted, with reporting and tasking protected using ChaCha20-Poly1305. After registration, the implant can receive updated configuration and dynamically targeted theft instructions from the operator.
Its capability set is extensive. SnappyClient can capture screenshots, log keystrokes, execute files, provide remote shell access, browse files and directories, manage processes, and exfiltrate stolen information. It can steal credentials, cookies, browser profile data, browser extension data, and information from other applications. Reported targeting includes major Chromium- and Gecko-based browsers, cryptocurrency wallet extensions, and desktop wallet applications. It has also been observed using techniques to obtain Chromium encryption material and bypass App-Bound Encryption protections, enabling theft of protected browser secrets. Additional functionality includes reverse proxy services for operator access, including hidden remote desktop and proxy-style channels.
Observed tasking and target selection indicate a strong focus on cryptocurrency-related activity, including wallet data theft and monitoring for crypto-related user behavior. SnappyClient has also been linked to campaigns affecting financial organizations. Code and tradecraft overlaps with HijackLoader have been reported, suggesting a possible developer or operational relationship between the two malware families.
C2 tracking
Derp observations, rolling seven-day window
Samples
28ffae9f7d8db57b6f08c709eefa1838b6d8fbe71ec2187c0c4b505675323d11 69b5b7c2373ae055a43657ce7f7444d8328c0421540e5a646226000c41653b9a 87765030bfc4b3b37bcdcefbf929797e8cac2461f99b2a64980917cd46b06e83 afaf65e5d79e245be0a522af0311ab76f74eea849cc1fc29d1b46b45da490f8a f74d0eb7c679ffc5ac173c9e5a3a9ab98216e0d73b0b772f1f307591affa3db7 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.