SnakeStealer

First seen
2019-01-01 00:00:00
Malware type
credential-stealer, keylogger, screen-capture, spyware
Family
Malware family
Profile updated
2026-07-07 15:33:40

Context

The SnakeStealer (currently advertised under an inaccurate name Snake Keylogger) is information stealing malware with many capabilities. Initially advertised on a Russian hacking forum in 2019, this .NET malware is capable of stealing credentials, monitoring the clipboard content, capturing screenshots, and keylogging. SnakeStealer is known for using multiple data exfiltration methods, including FTP, SMTP, and the Telegram API.

Reports & references

  • ESET — Eset Threat Report H1 2025 (report)

External references