Skip to content

Malware

SnappyClient

According to Zscaler, SnappyClient was first observed in December 2025.

SnappyClient is a Windows malware family.

Background

Zscaler reports that SnappyClient first appeared in December 2025. Written in C++, it is a C2 implant that can exfiltrate data and grant remote access. To evade endpoint security, it relies on several tricks, among them an Antimalware Scan Interface (AMSI) bypass plus Heaven's Gate, direct system calls, and transacted hollowing. The implant pulls two configuration files from its C2 server: one lists actions to run when a given condition is met, and the other names the applications to target for data theft. All of its traffic flows over a custom network protocol encrypted with ChaCha20-Poly1305.


Source: Malpedia (Fraunhofer FKIE).