According to Check Point’s Global Threat Index for July 2021, Snake Keylogger has surged in popularity in recent weeks to become the second-most prevalent malware strain globally.
First detected in November 2020, Snake Keylogger is a modular .NET keylogger and credential stealer.
Researchers say the malware’s primary function is to record users’ keystrokes on computer or mobile devices. Collected data is then transmitted to the cybercriminals and hackers deploying the malicious software.
Snake Keylogger infections pose a major threat to users’ privacy and online safety, as the malware can steal virtually all kinds of sensitive information. Similarly, it is widely regarded as a particularly evasive and persistent keylogger.
The analysis from Check Point reveals this is the first time Snake Keylogger has featured in the firm’s list of ‘Top 10’ malware strains.
Snake’s popularity has been growing rapidly following a spree of successful phishing campaigns. At present, the malware is available for purchase on a range of underground hacking forums, with buyers able to purchase the malware for as little as $25.
How to combat a Snake Keylogger attack
Researchers at Check Point revealed keylogger attacks are often highly effective due to our tendency to use the same password and username for different accounts.
After a particular log-in credential is breached, cybercriminals thereby gain access to all accounts which use the same password.
Maya Horowitz, VP Research at Check Point Software, said to stop these types of attacks, users should use a “unique option” for each of the different profiles.
“When it comes to password policies, choosing a strong, unique password for each service is the best advice, then even if the bad guys do get hold of one of your passwords, it won’t immediately grant them access to multiple sites and services,” she explained.
Recommended
- Comment | Security metrics made easy
- Credit card data breach releases a million people’s details as PR stunt
- Scottish businesses under threat as global ransomware attacks double
“Where possible, users should reduce the reliance on passwords alone, for example by implementing Multi-Factor Authentication (MFA) or Single-Sign on (SSO) technologies,” Horowitz added.
Critically, Horowitz urged users to remain vigilant when browsing the web or checking emails.
Keyloggers are often distributed via phishing emails. By looking out for the tell-tale signs of suspicious activity, users can avoid falling foul to hackers.
“It’s essential that users know to look out for small discrepancies such as misspellings in links and email addresses, and be educated to never click on suspicious links or open any unfamiliar attachments,” she said.
Examining mobile malware
The research from Check Point highlighted some of the top malware families which are circulating globally, as well as concerning statistics on the increased use of mobile malware.
Across July, xHelper was pinpointed as the most prevalent form of mobile malware globally, followed closely by AlienBot and Hiddad.
xHelper has been in use since March 2019, researchers said, and is used to download other malicious apps on mobile devices. Notably, the application is capable of hiding from the user and can reinstall itself in the event that the device owner removes it.
Meanwhile, Hiddad is an Android malware which repackages legitimate applications and releases them to a third-party store. The malware’s main function is to display ads.
However, researchers said it can also be used to gain access to key security details built into a device OS.





