Skip to content

SnappyClient

SnappyClient is a Windows-focused C++ command-and-control implant and remote access trojan first observed in late 2025.

Profile source: Mallory opens in a new tab

SnappyClient

Family profile

SnappyClient is a Windows-focused C++ command-and-control implant and remote access trojan first observed in late 2025. It is designed for stealthy persistence, long-term post-compromise access, surveillance, and data theft, with observed operations strongly associated with financially motivated cryptocurrency theft. The malware has been described both as a C2 framework and as a RAT because it combines operator-controlled remote access with modular theft and post-exploitation functions.

SnappyClient has been observed delivered via HijackLoader and in campaigns using fake software-update lures, spoofed telecommunications-themed download pages, spearphishing, and ClickFix-style social engineering chains. In one documented intrusion set, it was deployed through DLL sideloading using signed applications as cover, with HijackLoader unpacking and launching the final implant.

The malware supports persistence through scheduled tasks and Windows autorun mechanisms. It includes multiple defense-evasion features, including AMSI bypass through hooking, direct system calls, 64-bit execution techniques such as Heaven’s Gate, process injection, and tradecraft intended to reduce visibility to user-mode security tooling. It also supports single-instance control and can maintain encrypted local configuration and tasking data.

SnappyClient communicates with its command-and-control infrastructure over a custom TCP binary protocol. Traffic is compressed and encrypted, with reporting and tasking protected using ChaCha20-Poly1305. After registration, the implant can receive updated configuration and dynamically targeted theft instructions from the operator.

Its capability set is extensive. SnappyClient can capture screenshots, log keystrokes, execute files, provide remote shell access, browse files and directories, manage processes, and exfiltrate stolen information. It can steal credentials, cookies, browser profile data, browser extension data, and information from other applications. Reported targeting includes major Chromium- and Gecko-based browsers, cryptocurrency wallet extensions, and desktop wallet applications. It has also been observed using techniques to obtain Chromium encryption material and bypass App-Bound Encryption protections, enabling theft of protected browser secrets. Additional functionality includes reverse proxy services for operator access, including hidden remote desktop and proxy-style channels.

Observed tasking and target selection indicate a strong focus on cryptocurrency-related activity, including wallet data theft and monitoring for crypto-related user behavior. SnappyClient has also been linked to campaigns affecting financial organizations. Code and tradecraft overlaps with HijackLoader have been reported, suggesting a possible developer or operational relationship between the two malware families.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 9, 2026
Last activity
Aug 9, 2026
Feed role
C2
Host form
1 IP / 1 hostnames

Leading locations

  • GB1
  • NL1

Leading providers

  • GLOBAL CONNECTIVITY SOLUTIONS LLP1
  • SERVERS TECH FZCO1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

MITRE ATT&CK

SnappyClient in ATT&CK

48 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.