SnakeStealer Malware Tops Infostealer Detection Charts in 2025
According to the ESET Threat Report for the first half of 2025, SnakeStealer has emerged as the leading infostealer malware, surpassing established threats like Agent Tesla and Lumma Stealer. Originally appearing in 2019 as '404 Keylogger,' this malware operates under a Malware-as-a-Service (MaaS) model, allowing low-skilled attackers to rent its capabilities. It primarily spreads through phishing emails containing malicious attachments such as password-protected ZIPs, RTF, or ISO files, and is also found in pirated software. SnakeStealer is designed to siphon sensitive data, including login credentials, financial details, and cryptocurrency information, from compromised systems. Its key features include evasion techniques that terminate security processes, persistence mechanisms altering Windows boot configurations, and comprehensive surveillance tools like keylogging and screenshot capture. Stolen data is exfiltrated via FTP, HTTP, email, or Telegram bots. The malware's recent surge is attributed to its reliability, modular design, and adoption by underground communities following the decline of competitor support. ESET researchers highlight that SnakeStealer accounted for nearly one-fifth of global infostealer detections recently, emphasizing the need for robust cybersecurity measures to protect personal and corporate data from this persistent threat.
Wire timeline
SnakeStealer Malware Tops Infostealer Detection Charts in 2025
According to the ESET Threat Report for the first half of 2025, SnakeStealer has emerged as the leading infostealer malware, surpassing established threats like Agent Tesla and Lumma Stealer. Originally appearing in 2019 as '404 Keylogger,' this malware operates under a Malware-as-a-Service (MaaS) model, allowing low-skilled attackers to rent its capabilities. It primarily spreads through phishing emails containing malicious attachments such as password-protected ZIPs, RTF, or ISO files, and is also found in pirated software. SnakeStealer is designed to siphon sensitive data, including login credentials, financial details, and cryptocurrency information, from compromised systems. Its key features include evasion techniques that terminate security processes, persistence mechanisms altering Windows boot configurations, and comprehensive surveillance tools like keylogging and screenshot capture. Stolen data is exfiltrated via FTP, HTTP, email, or Telegram bots. The malware's recent surge is attributed to its reliability, modular design, and adoption by underground communities following the decline of competitor support. ESET researchers highlight that SnakeStealer accounted for nearly one-fifth of global infostealer detections recently, emphasizing the need for robust cybersecurity measures to protect personal and corporate data from this persistent threat.
WeLiveSecurity