Snake Keylogger - Daily Threat Report

Sunday, July 19, 2026

Daily Summary

10 new Snake Keylogger samples were captured today, a 141% surge above the 7-day average of 4, continuing an upward trend. This spike is driven almost entirely by a 7-fold increase in JavaScript-based payloads (8 of 10 samples), marking a clear shift from prior distribution methods.

7-Day Trend

Today’s 10 samples are 150% above the 7-day average of 4, reflecting a sustained rise from the typical 2-5 daily range seen over the past week. The trend is not a one-off spike-the past three days have steadily increased from 3 to 6 to 10, suggesting an active campaign rather than noise.

New Samples Detected

8 of today’s 10 samples use JavaScript (.js) files, a sharp deviation from the usual mix of Excel add-ins (.xll, .xlam) and executables (.exe). The .js files employ encoded string obfuscation (Base64 and XOR) and download the final payload from a URL. One .bat file contains a PowerShell download cradle, and the lone .exe is a packed variant using UPX 3.96.

Distribution Methods

The high .js volume suggests a shift in delivery: likely via email attachments labeled as invoices or order confirmations (e.g., “Invoice_2026-07-19.js”). Paired with the .bat with a PowerShell cradle, the campaign appears to target users who disable macro execution but still execute scripts-a common tactic in recent Snake Keylogger waves. No new phishing domains or URLs were identified in the distribution chain.

Detection Rate

On VirusTotal, 6 of the 8 .js samples have 3-5 detections (low), while the .exe has 10 detections (moderate). The low detection for script-based payloads indicates they evade signature-focused AVs. The UPX-packed .exe may bypass some static scanners, but dynamic analysis should catch it.

IOC Highlights

10 new IOCs were added today: 8 .js file hashes, 1 .bat hash, and 1 .exe hash. All are tagged as “snake_keylogger_2026-07-19.” No new C2 domains or IPs were observed, suggesting reuse of existing infrastructure from the past 14 days.

Security Analysis

The surge in .js payloads over traditional Office macros is notable-Snake Keylogger operators appear to be adapting to macro-blocking defenses by switching to JavaScript, which often bypasses email filters. This mirrors tactics seen in 2025’s “PurpleFox” campaigns. Recommend deploying user behavior analytics to flag unsolicited .js execution, and enforce AppLocker or WDAC policies to block script execution from untrusted directories (e.g., %TEMP%, %APPDATA%).

Further Reading

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)

More Snake Keylogger Reports

Recent Malware Reports