Applications of Snake Keylogger in Geopolitics: Abuse of Trusted Java Utilities in Cybercriminal Activities
A new phishing campaign using Snake Keylogger, a Russian-origin stealer, has been discovered targeting various victims including corporations, governments, and individuals. The campaign uses spear-phishing emails offering petroleum products, with malicious attachments exploiting the legitimate jsadebugd.exe binary through DLL sideloading to load Snake Keylogger. The attackers are leveraging current geopolitical tensions in the Middle East to expand their reach. The malware steals credentials from browsers and applications, collects system information, and exfiltrates data via SMTP. This campaign marks the first observed malicious use of jsadebugd.exe, indicating evolving tactics to evade detection.
Pulse ID: 686a64122fafa4b925fb6300
Pulse Link: https://otx.alienvault.com/pulse/686a64122fafa4b925fb6300
Pulse Author: AlienVault
Created: 2025-07-06 11:54:58
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
