Last seven days
- First activity
- Aug 9, 2026
- Last activity
- Aug 9, 2026
- Feed role
- C2
- Host form
- 1 IP / 1 hostnames
SnappyClient is a Windows-focused C++ command-and-control implant and remote access trojan first observed in late 2025.
Profile source: Mallory opens in a new tabSnappyClient
SnappyClient is a Windows-focused C++ command-and-control implant and remote access trojan first observed in late 2025. It is designed for stealthy persistence, long-term post-compromise access, surveillance, and data theft, with observed operations strongly associated with financially motivated cryptocurrency theft. The malware has been described both as a C2 framework and as a RAT because it combines operator-controlled remote access with modular theft and post-exploitation functions.
SnappyClient has been observed delivered via HijackLoader and in campaigns using fake software-update lures, spoofed telecommunications-themed download pages, spearphishing, and ClickFix-style social engineering chains. In one documented intrusion set, it was deployed through DLL sideloading using signed applications as cover, with HijackLoader unpacking and launching the final implant.
The malware supports persistence through scheduled tasks and Windows autorun mechanisms. It includes multiple defense-evasion features, including AMSI bypass through hooking, direct system calls, 64-bit execution techniques such as Heaven’s Gate, process injection, and tradecraft intended to reduce visibility to user-mode security tooling. It also supports single-instance control and can maintain encrypted local configuration and tasking data.
SnappyClient communicates with its command-and-control infrastructure over a custom TCP binary protocol. Traffic is compressed and encrypted, with reporting and tasking protected using ChaCha20-Poly1305. After registration, the implant can receive updated configuration and dynamically targeted theft instructions from the operator.
Its capability set is extensive. SnappyClient can capture screenshots, log keystrokes, execute files, provide remote shell access, browse files and directories, manage processes, and exfiltrate stolen information. It can steal credentials, cookies, browser profile data, browser extension data, and information from other applications. Reported targeting includes major Chromium- and Gecko-based browsers, cryptocurrency wallet extensions, and desktop wallet applications. It has also been observed using techniques to obtain Chromium encryption material and bypass App-Bound Encryption protections, enabling theft of protected browser secrets. Additional functionality includes reverse proxy services for operator access, including hidden remote desktop and proxy-style channels.
Observed tasking and target selection indicate a strong focus on cryptocurrency-related activity, including wallet data theft and monitoring for crypto-related user behavior. SnappyClient has also been linked to campaigns affecting financial organizations. Code and tradecraft overlaps with HijackLoader have been reported, suggesting a possible developer or operational relationship between the two malware families.
C2 tracking
Derp observations, rolling seven-day window
Samples
5f3022e5f4908aa19505122a91b56e1a857b608545412253d2e44386bedc95f2 69b5b7c2373ae055a43657ce7f7444d8328c0421540e5a646226000c41653b9a 8102497012e4072c65a9e26ffb835340d917c1272c02f232d866b7f859728bd0 87765030bfc4b3b37bcdcefbf929797e8cac2461f99b2a64980917cd46b06e83 c676837872a816e8d93180440c74fee75a987b48f92871bac822785d32ab29b6 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.