SnappyClient: malware with broad data theft and remote control capability
Zscaler ThreatLabz has analysed SnappyClient, a C++ command-and-control implant delivered via the HijackLoader loader in targeted campaigns. Victims are lured to malicious or impersonation websites that trigger download and execution of the payload. Once installed it establishes persistence and communicates with its C2 server over a custom encrypted protocol, with capabilities including keylogging, screenshot capture, clipboard monitoring and exfiltration of data from browsers, extensions and local applications.
What this means for your organisation
The combination of remote control and broad data collection means a single compromised machine can hand the attacker both company secrets and a foothold to move onward. Delivery happens through websites that resemble something the user expects rather than an email attachment, which weakens controls that only inspect mail. Encrypted C2 traffic means detection in practice has to happen on the endpoint.
Berigo recommends
- Ensure every client has endpoint detection that is actually monitored, not merely installed.
- Restrict which programs users can execute from download folders and temporary directories.
- Consider egress and DNS controls so communication with unknown infrastructure can be detected.
- Define in advance what happens when a client is suspected compromised: isolation, evidence preservation, credential rotation.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch