Last seven days
- First activity
- Sep 21, 2026
- Last activity
- Sep 24, 2026
- Feed role
- C2
- Host form
- 1 IP / 1 hostnames
SnappyClient, also tracked as SilabRAT, is a C++ Windows remote-access trojan and command-and-control implant first observed in December 2025.
Profile source: Mallory opens in a new tabSnappyClient
SnappyClient, also tracked as SilabRAT, is a C++ Windows remote-access trojan and command-and-control implant first observed in December 2025. It is designed for persistent post-compromise access, surveillance, data theft, and financially motivated cryptocurrency theft. It can capture screenshots, log keystrokes, provide remote shell and remote file-browsing functions, manage processes and files, execute files, steal browser passwords, cookies, profiles, extensions, and application data, and exfiltrate collected information. It also supports reverse-proxy services including VNC, SOCKS5, FTP, and RLOGIN.
SnappyClient targets browser and cryptocurrency activity, including wallet extensions and cryptocurrency applications, and can monitor clipboard content and cryptocurrency-related window titles. It can obtain Chromium encryption material through process-hollowing techniques to bypass Chromium App-Bound Encryption protections. The implant communicates through a custom TCP protocol using Snappy compression and ChaCha20-Poly1305 encryption, and can receive updated configuration and target definitions from its command-and-control infrastructure.
The malware employs AMSI bypassing, direct system calls via Heaven’s Gate, clean system-library mapping, process injection or transacted hollowing, and other anti-analysis measures. Persistence is established using scheduled tasks or Windows autorun mechanisms. Observed intrusion chains have used HijackLoader to deploy SnappyClient, including fake telecommunications-themed download sites, ClickFix social engineering, and spear-phishing campaigns using trojanized installers and DLL side-loading. Code and tradecraft overlaps with HijackLoader have been observed, although a common developer relationship has not been conclusively established.
C2 tracking
Derp observations, rolling seven-day window
Samples
0b9bce33086d27ab4d255a62c63023a8f2230bdeeb2306263947da4835475153 15c021424ce853eb5d37f3f8c1d9887d8e974723bb46175e25a9258ea24d2b50 674b757f60e7d26df7c5d0a79a5e51ebea6134a1873220678f000214d412676a 82b92b518ff8296b2e597ba98383d1fc1a2187a20ec11ed26ed9a4b9ab3c22ed f3cb6f397ca3ea712bd36d5401ae91ef48f2df6ee92a6b8e93eceb589394de60 06286740570768e1387e4a6546941a5215f355ad97b8521119ab5f101d821a36 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.