Snip3 is a sophisticated information stealer malware first publicly documented by researchers at Proofpoint in November 2022, believed to be operated by a financially motivated threat actor tracked as TA569. It belongs to the stealer and loader category, primarily designed to exfiltrate credentials, cookies, and sensitive data from web browsers and cryptocurrency wallets before deploying secondary payloads.
Snip3 propagates primarily through malicious phishing emails containing weaponized Microsoft Excel attachments (XLL files) that exploit the Excel Add-In execution mechanism. Once opened, the malware downloads a PowerShell-based loader that injects a .NET-based stealer into memory, avoiding writing artifacts to disk. The stealer targets credentials from Chromium-based browsers, Firefox, and multiple cryptocurrency wallet extensions, exfiltrating data over HTTPS to a command-and-control (C2) infrastructure hosted on compromised legitimate web servers. Persistence is achieved via scheduled tasks or registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include checking for sandbox environments, disabling Windows Defender via registry modifications, and using encrypted strings to hinder static analysis (MITRE ATT&CK technique T1059.001 for PowerShell, T1055.001 for process injection).
Snip3 emerged in late 2022 and was linked to the TA569 group, previously associated with the Bumblebee loader. A major campaign in November 2022 targeted North American manufacturing and logistics firms, using invoice-themed lures. No specific CVEs have been directly exploited; instead, social engineering and Excel add-in execution (CVE-2017-0199-style techniques) are used. No law enforcement actions have been reported as of early 2025.
Known indicators include file hashes for malicious XLL attachments identified in Proofpoint analysis (e.g., SHA256 hashes documented in Proofpoint's November 2022 report) and network IOCs such as C2 domains incorporating random alphanumeric strings. Behavioral signatures include anomalous PowerShell execution spawning from Excel, registry modifications to disable Windows Defender, and outbound HTTPS connections to non-standard ports. Specific mutex names have not been publicly documented.
Snip3 poses a high risk due to its ability to exfiltrate sensitive credentials and cryptocurrency wallet data, leading to financial theft and account compromise. The primary impact is data exfiltration; the malware has also been observed dropping additional payloads such as remote access tools. Affected sectors include manufacturing, logistics, and financial services, according to Proofpoint's threat intelligence.
Organizations should block Excel add-in files (.xll) from email attachments, enforce application whitelisting with ASR rules, and deploy endpoint detection and response (EDR) solutions capable of detecting PowerShell-based injection. Regular user awareness training against phishing with invoice lures is critical. Proofpoint recommends monitoring for outbound HTTPS traffic to anomalous domains and enabling Windows Defender real-time protection.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.