HomeSecuritySnakeKeylogger steals sensitive data via emails

SnakeKeylogger steals sensitive data via emails

Emerging from a recent wave of targeted attacks, SnakeKeylogger has emerged as a powerful infostealer that exploits PowerShell and social engineering techniques. The malware's handlers craft convincing spear-phishing emails using aliases such as 'CPA-Payment Files', posing as reputable financial and research firms. Recipients encounter ISO or ZIP containing a seemingly innocent BAT script. Once executed, this script downloads and launches a PowerShell payload designed to collect keystrokes and system information before exporting data to a remote server.

See also: Beware! New advanced variant of Snake Keylogger malware

SnakeKeylogger

Gen Threat Labs analysts noted the malware’s seamless integration with legitimate Windows utilities and custom scripting for stealth and rapid deployment. Upon opening the attachment, victims unwittingly activate a BAT file that bypasses standard execution policies and hides visible windows, allowing SnakeKeylogger to operate without arousing suspicion.

The PowerShell script, once loaded, establishes persistent access, creating scheduled tasks and registry entries, ensuring that the malware survives reboots and evades superficial incident response efforts. Beyond the initial delivery, SnakeKeylogger's impact lies in its minimalist yet effective data collection routines.

See also: VIPKeyLogger: Steals credentials through dangerous Office files

SnakeKeylogger steals sensitive data via emails

Once activated, the script calls Windows API functions to capture keystrokes, clipboard contents, and active window titles. The collected information is aggregated and encrypted before being transmitted to a command and control server.

Observed IoCs include SHA256 hashes of the BAT payload and the PowerShell script URL, indicative of an ongoing campaign. The SnakeKeylogger infection chain relies on a two-stage loader. The initial BAT script exploits PowerShell’s unfettered execution to retrieve the keylogger’s core module. Within the PowerShell payload, the Add-Type command synthesizes C# code in-place, injecting functions such as GetAsyncKeyState for low-level keystroke interception.

See also: Nova Keylogger steals credentials and captures screenshots 

SnakeKeylogger steals sensitive data via emails

Persistence is achieved through a scheduled task entry that re-deploys the keylogger on every user logon and is integrated into legitimate Windows maintenance processes, making detection more complex. Continuous monitoring and timely updates to endpoint protection policies are recommended to address this evolving threat.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS