Skip to main content
Mallory
Back to malware
MalwareRansomwareUsed by 4 actors

Snake Keylogger

Snake Keylogger is a .NET-based information stealer and keylogger first observed in 2020. The provided content describes it as a commodity or subscription-style stealer used in phishing and malspam campaigns, including spear-phishing operations. Reported targeting includes the oil industry, Turkey's defense and aerospace sectors, and broader credential-theft campaigns; the content also notes use by clusters tracked as TA2715 and TA2536. Snake Keylogger is associated with phishing-delivered attachments and archive/container-based execution patterns, and one report cited DLL sideloading as a loading technique.

Its documented capabilities include keystroke logging, theft of browser-stored information and credentials, browser cookies, geolocation data, and general system information. The content also links it to access of browser password stores and Discord LevelDB data, consistent with credential and user-data theft objectives. Exfiltration methods explicitly mentioned in the content include FTP, SMTP, and HTTP/web APIs.

Behaviorally, the content associates Snake Keylogger with browser credential theft, victim network and geolocation discovery via external IP-check services, network connections discovery via netsh, suspicious DNS queries to abused web services, FTP communications from non-standard process paths, and abuse patterns involving .NET-related utilities and signed-binary proxy execution tradecraft. Splunk reporting notes substantial overlap in tradecraft and tooling between Snake Keylogger and VIP Keylogger, including similar credential-theft goals, managed-code implementation, and obfuscation.

The content does not provide a definitive attribution to a single threat actor, but it does state that Snake Keylogger has been observed in campaigns linked to TA2715 and TA2536. One cited report describes a campaign as involving a 'Russian origin stealer programmed in .NET,' but broader attribution is not established in the provided material.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
TA2536

... TA2715 and TA2536, both of which favored Snake Keylogger ...

via the hacker newsthehackernews.com
TA2715

... TA2715 and TA2536, both of which favored Snake Keylogger ...

via the hacker newsthehackernews.com
UAC-00411

“The S2 Group’s intelligence team has identified… a new phishing campaign by Snake Keylogger, a Russian origin stealer programmed in .NET… The campaign… using spearphishing emails offering oil products… [and] the Sideloading Dll technique to load Snake Keylogger…”

via lab52 bloglab52.io
TA558.2

“The S2 Group’s intelligence team has identified… a new phishing campaign by Snake Keylogger, a Russian origin stealer programmed in .NET… The campaign… using spearphishing emails offering oil products… [and] the Sideloading Dll technique to load Snake Keylogger…”

via lab52 bloglab52.io
MITRE ATT&CK

Techniques & procedures

16 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence2

Phishing lures were sent through email platforms including Microsoft O365, Roundcube, and Zimbra, as well as messaging apps like Signal, WhatsApp, and Telegram.

T1566.001Spearphishing AttachmentEvidence1

Payloads arrived through file types including SVG, PNG, LNK, JS, and HTA files, often hosted on legitimate services like Dropbox, Google Drive, and Cloudflare Tunnels to bypass network defenses.

Execution

1 technique
T1059.005Visual BasicEvidence1

Annotations ID Technique Tactic T1059.005 Visual Basic Execution

Persistence

1 technique
T1543.003Windows ServiceEvidence1

XMRIG Driver Loaded ... T1543.003 ... Windows Suspicious Driver Loaded Path

Privilege Escalation

1 technique
T1543.003Windows ServiceEvidence1

XMRIG Driver Loaded ... T1543.003 ... Windows Suspicious Driver Loaded Path

Stealth

3 techniques
T1036MasqueradingEvidence1

Executables Or Script Creation In Temp Path ... T1036

T1218System Binary Proxy ExecutionEvidence1

Execution of well-known .NET-related utilities when the parent appears to be a script launched from user-writable or non-standard locations is consistent with signed-binary proxy execution tradecraft (MITRE ATT&CK T1218) seen in stealer and loader workflows.

T1218.009Regsvcs/RegasmEvidence1

The following analytic detects regasm.exe spawning a child process... This activity is significant because regasm.exe spawning a process is rare and can indicate an attempt to bypass application control mechanisms.

Credential Access

4 techniques
T1056Input CaptureEvidence1

“SnakeStealer… can log keystrokes, steal saved credentials, take screenshots, and collect clipboard data.”

T1056.001KeyloggingEvidence2

Description This analytic story contains detections that help security analysts identify endpoint activity that may be associated with VIP Keylogger, a .NET-based information stealer and keylogger

T1552Unsecured CredentialsEvidence1

Generated datasets for snakey keylogger outlook reg access in attack range... Dataset_1 Path: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/snakey_keylogger_outlook_reg_access/snakekeylogger_4663.log

T1555Credentials from Password StoresEvidence1

The malware targets email clients like Microsoft Outlook, extracting credentials for protocols such as IMAP, POP3, and SMTP from the Windows Registry.

Discovery

1 technique
T1049System Network Connections DiscoveryEvidence1

Windows System Network Connections Discovery Netsh ... Anomaly Endpoint T1049 Windows Post-Exploitation, Prestige Ransomware, Snake Keylogger

Collection

4 techniques
T1056Input CaptureEvidence1

“SnakeStealer… can log keystrokes, steal saved credentials, take screenshots, and collect clipboard data.”

T1056.001KeyloggingEvidence2

Description This analytic story contains detections that help security analysts identify endpoint activity that may be associated with VIP Keylogger, a .NET-based information stealer and keylogger

T1113Screen CaptureEvidence2

Designed for electronic espionage, the Trojan is capable of intercepting keyboard inputs, capturing screenshots, and retrieving active application lists.

T1115Clipboard DataEvidence1

“SnakeStealer… can… collect clipboard data.”

Command and Control

1 technique
T1071.003Mail ProtocolsEvidence1

T1071.003 Mail Protocols is a sub-technique of Application Layer Protocols (T1071) in the MITRE ATT&CK framework, under the Command and Control tactic.

Exfiltration

1 technique
T1048Exfiltration Over Alternative ProtocolEvidence1

The stolen information is exfiltrated to cybercriminals through multiple channels, including email, demonstrating its use of mail protocols to evade detection.

INDICATORS OF COMPROMISE

IOCs tracked for this family

40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
3 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
34 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
3 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching40

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution4

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping16

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.