216.73.216.6

SnakeKeylogger: Multistage Info Stealer Malware Analysis & Prevention

· Published 25/03/2025 10:46 · Modified 25/03/2025 13:19

Export JSON

Essential information

Published
25/03/2025 10:46
Modified
25/03/2025 13:19
Tags
2025-03-25 apache-server credential-theft info-stealer multi-stage obfuscation process-hollowing snakekeylogger spam-email
Related entities
2 observables, 1 intrusion sets (apt), 16 techniques (mitre), 1 malware

Description

is a highly active credential-stealing malware targeting individuals and businesses. It employs a infection chain, starting with malicious spam emails containing .img files. The malware uses sophisticated techniques like process hollowing and to evade detection. It targets various applications, including web browsers, email clients, and FTP software, to harvest sensitive data and credentials. The campaign utilizes an Apache server for malware distribution, regularly updating encrypted payloads. 's primary objective is to collect Outlook profile credentials, email configurations, and stored authentication details, which can be exploited for business email compromise or sold on underground markets.

External references