Skip to content

SnappyClient

SnappyClient, also tracked as SilabRAT, is a C++ Windows remote-access trojan and command-and-control implant first observed in December 2025.

Profile source: Mallory opens in a new tab

SnappyClient

Family profile

SnappyClient, also tracked as SilabRAT, is a C++ Windows remote-access trojan and command-and-control implant first observed in December 2025. It is designed for persistent post-compromise access, surveillance, data theft, and financially motivated cryptocurrency theft. It can capture screenshots, log keystrokes, provide remote shell and remote file-browsing functions, manage processes and files, execute files, steal browser passwords, cookies, profiles, extensions, and application data, and exfiltrate collected information. It also supports reverse-proxy services including VNC, SOCKS5, FTP, and RLOGIN.

SnappyClient targets browser and cryptocurrency activity, including wallet extensions and cryptocurrency applications, and can monitor clipboard content and cryptocurrency-related window titles. It can obtain Chromium encryption material through process-hollowing techniques to bypass Chromium App-Bound Encryption protections. The implant communicates through a custom TCP protocol using Snappy compression and ChaCha20-Poly1305 encryption, and can receive updated configuration and target definitions from its command-and-control infrastructure.

The malware employs AMSI bypassing, direct system calls via Heaven’s Gate, clean system-library mapping, process injection or transacted hollowing, and other anti-analysis measures. Persistence is established using scheduled tasks or Windows autorun mechanisms. Observed intrusion chains have used HijackLoader to deploy SnappyClient, including fake telecommunications-themed download sites, ClickFix social engineering, and spear-phishing campaigns using trojanized installers and DLL side-loading. Code and tradecraft overlaps with HijackLoader have been observed, although a common developer relationship has not been conclusively established.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 21, 2026
Last activity
Sep 24, 2026
Feed role
C2
Host form
1 IP / 1 hostnames

Leading locations

  • GB1
  • NL1

Leading providers

  • GLOBAL CONNECTIVITY SOLUTIONS LLP1
  • SERVERS TECH FZCO1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

MITRE ATT&CK

SnappyClient in ATT&CK

52 distinct techniques

Techniques

52 techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.