TF-1932577
high
📛 Threat Title
SnappyClient: Domain name that delivers a malware payload leebin101.com
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: SnappyClient (aliases: SilabRAT). Confidence: 100. First seen: 2026-09-25 06:28:02 UTC. Reporter: freeslugga. Tags: SnappyClient.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
leebin101.com
IOC database
- Type
- domain
- Value
leebin101.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain name that delivers a malware payload attributed to SnappyClient
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: SnappyClient (aliases: SilabRAT). Confidence: 100. First seen: 2026-09-25 06:28:02 UTC. Reporter: freeslugga. Tags: SnappyClient.
Remediations (10)
-
web:any.run
SnappyClient's public history is still short, but it has already shown signs of active development and diversified delivery: December 2025 — Zscaler ThreatLabz first identifies SnappyClient as a distinct malware family, delivered via HijackLoader.
-
web:community.gurucul.com
In December 2025, Labz discovered a new C2 implant called SnappyClient , delivered via HijackLoader. SnappyClient is a C++-based malware that enables remote access and extensive data theft. Its capabilities include keylogging, screenshots, remote terminal access, and stealing data from browsers and applications.
-
web:cybersecuritynews.com
A dangerous new malware implant called SnappyClient has quietly emerged as a serious threat to Windows users, combining remote access, data theft, and sophisticated evasion techniques in one compact C++ package.
-
web:ismalicious.com
11 indicators (2 domains , 6 IPs, 0 URLs, 3 hashes) attributed to the SnappyClient malware family.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Zscaler, SnappyClient was first observed in December 2025. It is a C++-based C2 implant with the ability to steal data and provide remote access. SnappyClient employs multiple evasion techniques to hinder endpoint security detection, including an Antimalware Scan Interface (AMSI) bypass, as well as implementing Heaven's Gate, direct system calls, and transacted hollowing ...
-
web:maltiverse.com
SnappyClient First seen 2025-12-01 00:00:00 Malware type rat, backdoor Family Malware family Related IoCs 16 (16 malicious) Last IoC activity 2026-09-15 11:21:28 Profile updated 2026-07-07 15:05:26 Targeted industries: government-and-public-sector technology-and-telecommunications financial-services Context According to Zscaler, SnappyClient was first observed in December 2025. It is a C++ ...
-
web:malware.news
IntroductionIn December 2025, Zscaler ThreatLabz identified a new command-and-control (C2) framework implant that we track as SnappyClient , which was delivered using HijackLoader. SnappyClient has an extended list of capabilities including taking screenshots, keylogging, a remote terminal, and data theft from browsers, extensions, and other applications. In this blog post, ThreatLabz provides ...
-
web:securityboulevard.com
IntroductionIn December 2025, Zscaler ThreatLabz identified a new command-and-control (C2) framework implant that we track as SnappyClient , which was delivered using HijackLoader. SnappyClient has an extended list of capabilities including taking screenshots, keylogging, a remote terminal, and data theft from browsers, extensions, and other applications. In this blog post, ThreatLabz provides ...
-
web:urlhaus.abuse.ch
URLhaus Database URLhaus tries to identify the malware associated with the payload served by a certain malware URL. In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as SnappyClient . Database Entry
-
web:www.zscaler.com
In conclusion, ThreatLabz has identified a new malware family that we track as SnappyClient , delivered via HijackLoader. SnappyClient operates as a C2 framework implant, with remote access and data theft capabilities.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.