216.73.217.22

Evolving Snake Keylogger Variant

· Published 20/02/2025 08:49 · Modified 20/02/2025 08:58

Export JSON

Essential information

Published
20/02/2025 08:49
Modified
20/02/2025 08:58
Tags
2025-02-20 404 keylogger ai detection autoit credential-theft fortisandbox keylogging paix process-hollowing snake keylogger
Related entities
3 observables, 20 techniques (mitre), 2 malware, 4 others

Description

A new variant of , identified as /Injector.GTY!tr, has been detected by v5.0. This malware has attempted over 280 million infections, primarily targeting China, Turkey, Indonesia, Taiwan, and Spain. steals sensitive information from popular web browsers by logging keystrokes, capturing credentials, and monitoring the clipboard. It exfiltrates data to its command-and-control server using SMTP and Telegram bots. 's advanced AI engine, , detected the malware through static and dynamic analysis, revealing its use of for obfuscation, process hollowing techniques, and persistence mechanisms. The keylogger also employs specialized modules to steal credit card details and leverages the SetWindowsHookEx API for keystroke capture.

External references