Security researchers have discovered Nova , an evolution of the Snake Keylogger malware family , that exhibits advanced data-stealing capabilities and improved evasion techniques.
See also: North Korean hackers Kimsuky use new malware KLogEXE and FPSpy

This new variant represents a significant advancement in malware development, posing increased risks to both personal and corporate systems.
Snake Keylogger, a .NET- based malware discovered in November 2020, is known for stealing credentials and recording keystrokes.
It is mainly spread through phishing using malicious Office documents or PDFs that provide PowerShell scripts for download. Once activated, it logs keystrokes, steals stored credentials, captures screenshots, and extracts data from the clipboard.
By 2024, Snake Keylogger has upgraded its tactics with techniques such as process hollowing and highly obfuscated code to evade detection. It now uses a suspended child process to inject payload , making it harder to detect and block by security tools. Reports indicate that its prevalence is increasing, posing an increasing risk to personal and corporate cybersecurity .
Nova Keylogger, written in VB.NET , uses multiple layers of protection, including Net Reactor Obfuscator and AutoIt -based protectors . The malware uses process hollowing techniques to inject its payload into suspended processes, making detection more difficult for security solutions.
See also: Kimsuky hackers use malicious Chrome extension to steal data
One of Nova's key developments involves the use of the hollowing process, where it injects the payload into a suspended child process, making it harder for antivirus programs to detect.

Additionally, Nova Keylogger uses highly obfuscated code, using tools such as Net Reactor Obfuscator to further obscure its functionality. Reports from 2024 highlight a significant increase in zero-day associated with this malware, highlighting its growing threat level.
The analysis performed in ANY.RUN Interactive Sandbox reveals Nova's behavior in detail.
The malware initiates HTTP requests to services such as checkip.dyndns.org to verify the victim's IP address and uses DNS requests to reallyfreegeoip.org to determine the country of the infected device.
The main technical features include:
- Comprehensive collection of credentials from major browsers, including Chrome, Firefox, Edge, and Opera
- Email client targeting capabilities for Outlook, Thunderbird, and Foxmail
- Advanced Windows product key extraction via registry manipulation
- Advanced clipboard monitoring and data extraction systems
See also: Microsoft Exchange Server: Vulnerabilities exploited to distribute keylogger
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Keylogger malware poses a serious risk to the security of personal information. This type of malware is capable of recording everything you type on your computer, including passwords, credit card information, and other sensitive information. This information can be used by malicious users for fraud, identity theft, and other nefarious purposes. To protect yourself from keylogger malware, it is important to use up-to-date security software, avoid acquiring software from untrusted sources , and be careful about how you share your personal information online.
Source: cybersecuritynews
