Deep Analysis of Snake Keylogger’s New Variant


Fortinet’s FortiGuard Labs recently caught a phishing campaign in the wild with a malicious Excel document attached to the phishing email. Fortinet researchers performed a deep analysis on the campaign and discovered that it delivers a new variant of Snake Keylogger.

Snake Keylogger (aka “404 Keylogger” or “KrakenKeylogger”) is a subscription-based keylogger with many capabilities. It is a .NET-based software originally sold on a hacker forum. Once executed on a victim’s computer, it has the ability to steal sensitive data, including saved credentials from web browsers and other popular software, the system clipboard, and basic device information. It can also log keystrokes and capture screenshots.

Read more…
Source: Fortinet


Sign up for our Newsletter


Related:

  • Windows Downdate: Downgrade Attacks Using Windows Updates

    August 9, 2024

    A version-rollback vulnerability has been discovered by a cybersecurity researcher that allows a fully patched Windows machine to be downgraded to older version, allowing the exploitation of previously patched zero-days and vulnerabilities. Alon Leviev unveiled his findings at Black Hat USA 2024 and DEF CON 32 (2024) as a tool named Windows Downdate. Leviev started their journey ...

  • Security company ADT announces security breach of customer data

    August 9, 2024

    Electronic surveillance equipment provider ADT filed a form 8-K with the Security and Exchange Commision (SEC) to report “a cybersecurity incident during which unauthorized actors illegally accessed certain databases containing ADT customer order information.” ADT filed the 8-K on August 7, adding that the incident happened “recently,” but refraining from providing an exact date. The company ...

  • UK police commissioner threatens to extradite, jail US citizens over online posts

    August 9, 2024

    London’s Metropolitan Police chief warned that officials will not only be cracking down on British citizens for commentary on the riots in the U.K., but on American citizens as well. “We will throw the full force of the law at people. And whether you’re in this country committing crimes on the streets or committing crimes from ...

  • JG Summit Holdings probing ‘possible’ cyber attack

    August 9, 2024

    Gokongwei-led conglomerate JG Summit Holdings Inc. is investigating an alleged cybersecurity attack which was claimed to have affected thousands of the company’s computers. RansomHub, which was supposedly responsible for the attack, expressed frustration over being ignored by JG Summit and was threatening to initiate additional attacks if its demands were not met, according to Deep Web ...

  • Royal Ransomware Actors Rebrand as “BlackSuit”

    August 8, 2024

    The FBI and CISA recently published an update to the joint Cybersecurity Advisory “#StopRansomware: Royal Ransomware.” The updated advisory provides network defenders with recent and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) associated with BlackSuit variants (previously Royal). FBI investigations identified these TTPs and IOCs as recently as July 2024. See ...

  • UK: Woman arrested for ‘sharing inaccurate information about identity of Southport attacker’

    August 8, 2024

    A woman has been arrested in relation to a social media post containing ‘inaccurate information about the identity of the attacker’ in the Southport stabbings. The 55-year-old woman from near Chester, was arrested on Thursday (August 8). She was taken into custody on suspicion of publishing written material to stir up racial hatred and false communications. ...