Emerging from a recent wave of targeted attacks, SnakeKeylogger has emerged as a powerful infostealer that exploits PowerShell and social engineering techniques. The malware's handlers craft convincing spear-phishing emails using aliases such as 'CPA-Payment Files', posing as reputable financial and research firms. Recipients encounter ISO or ZIP containing a seemingly innocent BAT script. Once executed, this script downloads and launches a PowerShell payload designed to collect keystrokes and system information before exporting data to a remote server.
See also: Beware! New advanced variant of Snake Keylogger malware

Gen Threat Labs analysts noted the malware’s seamless integration with legitimate Windows utilities and custom scripting for stealth and rapid deployment. Upon opening the attachment, victims unwittingly activate a BAT file that bypasses standard execution policies and hides visible windows, allowing SnakeKeylogger to operate without arousing suspicion.
The PowerShell script, once loaded, establishes persistent access, creating scheduled tasks and registry entries, ensuring that the malware survives reboots and evades superficial incident response efforts. Beyond the initial delivery, SnakeKeylogger's impact lies in its minimalist yet effective data collection routines.
See also: VIPKeyLogger: Steals credentials through dangerous Office files

Once activated, the script calls Windows API functions to capture keystrokes, clipboard contents, and active window titles. The collected information is aggregated and encrypted before being transmitted to a command and control server.
Observed IoCs include SHA256 hashes of the BAT payload and the PowerShell script URL, indicative of an ongoing campaign. The SnakeKeylogger infection chain relies on a two-stage loader. The initial BAT script exploits PowerShell’s unfettered execution to retrieve the keylogger’s core module. Within the PowerShell payload, the Add-Type command synthesizes C# code in-place, injecting functions such as GetAsyncKeyState for low-level keystroke interception.
See also: Nova Keylogger steals credentials and captures screenshots

Persistence is achieved through a scheduled task entry that re-deploys the keylogger on every user logon and is integrated into legitimate Windows maintenance processes, making detection more complex. Continuous monitoring and timely updates to endpoint protection policies are recommended to address this evolving threat.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
