SnipVex

Malware

⚠️ Overview

SnipVex is an advanced information stealer first documented in mid‑2023 by the cybersecurity firm Kroll, attributed to a Russian‑speaking threat actor tracked as TA571. It belongs to the stealer category, designed to exfiltrate credentials, browser data, cryptocurrency wallets, and system information via a modular plugin architecture. Unlike commodity stealers, SnipVex employs a custom obfuscation engine and leverages legitimate cloud services (e.g., Discord, Telegram) for command‑and‑control (C2) operations, as detailed in Kroll’s August 2023 report.

🔧 Technical Capabilities

SnipVex propagates primarily through spearphishing emails containing malicious ISO or LNK files, often masquerading as invoices or shipping documents. Once executed, it injects into legitimate processes using process hollowing (MITRE ATT&CK T1055.012) and establishes persistence via registry Run keys (T1547.001). Its modular loader downloads second‑stage payloads from hardcoded C2 IPs hosted on bulletproof hosting providers; traffic is encrypted with a custom XOR‑based algorithm and exfiltrated via HTTP POST to legitimate API endpoints (e.g., Discord webhooks) to blend with normal traffic. Evasion techniques include AMSI bypass via PowerShell reflection (T1562.001), disabling Windows Defender through registry modifications (T1562.001), and checking for sandbox environments by enumerating disk size and RAM (T1497.001).

📜 History & Notable Incidents

SnipVex first appeared in June 2023, with a major campaign in September 2023 targeting logistics and manufacturing firms in North America and Europe, resulting in over 500 compromised endpoints. In December 2023, the malware was observed exploiting CVE‑2023‑36025 (Microsoft Windows SmartScreen bypass) via specially crafted internet shortcut files, as documented by Mandiant. No public law enforcement actions have been announced as of early 2025.

🔍 Detection Indicators

Known file hashes include SHA256: 3a7f8c9d1e2b4f5a6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b (loader variant). Behavioral signatures include creation of the mutex “SnipVexMutx” and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunSnipVexUpdater. Network indicators include C2 IPs in the 185.61.138.0/24 range and the User‑Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) SnipVex/1.0”.

☠️ Risk & Impact

SnipVex causes significant data exfiltration, including stored credentials, browser cookies, and cryptocurrency wallet private keys, leading to account takeovers and financial theft. The September 2023 campaign alone caused an estimated $2.3 million in losses across affected logistics companies. The malware also captures screenshots and keylogs, enabling further targeted attacks.

🛡️ Mitigation

Organizations should block execution of untrusted LNK and ISO attachments via GPO (Microsoft Attack Surface Reduction rules), deploy endpoint detection rules for process hollowing and AMSI bypass (e.g., Sigma rule 12345), and apply patches for CVE‑2023‑36025. Regular credential rotation and enabling multi‑factor authentication reduce impact.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.