Snip3

S1086

Malware.View on attack.mitre.org

About this malware

Snip3 is a sophisticated crypter-as-a-service that has been used since at least 2021 to obfuscate and load numerous strains of malware including AsyncRAT, Revenge RAT, Agent Tesla, and NETWIRE.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1027
Obfuscated Files or Information

Snip3 has the ability to obfuscate strings using XOR encryption.

T1027.001
Binary Padding

Snip3 can obfuscate strings using junk Chinese characters.

T1047
Windows Management Instrumentation

Snip3 can query the WMI class `Win32_ComputerSystem` to gather information.

T1055.012
Process Hollowing

Snip3 can use RunPE to execute malicious payloads within a hollowed Windows process.

T1059.001
PowerShell

Snip3 can use a PowerShell script for second-stage execution.

T1059.005
Visual Basic

Snip3 can use visual basic scripts for first-stage execution.

T1082
System Information Discovery

Snip3 has the ability to query `Win32_ComputerSystem` for system information.

T1102
Web Service

Snip3 can download additional payloads from web services including Pastebin and top4top.

T1104
Multi-Stage Channels

Snip3 can download and execute additional payloads and modules over separate communication channels.

T1105
Ingress Tool Transfer

Snip3 can download additional payloads to compromised systems.

T1140
Deobfuscate/Decode Files or Information

Snip3 can decode its second-stage PowerShell script prior to execution.

T1189
Drive-by Compromise

Snip3 has been delivered to targets via downloads from malicious domains.

T1204.001
Malicious Link

Snip3 has been executed through luring victims into clicking malicious links.

T1204.002
Malicious File

Snip3 can gain execution through the download of visual basic files.

T1497.001
System Checks

Snip3 has the ability to detect Windows Sandbox, VMWare, or VirtualBox by querying `Win32_ComputerSystem` to extract the `Manufacturer` string.

View all 20 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Morphisec Snip3 May 2021 Open source
    Lorber, N. (2021, May 7). Revealing the Snip3 Crypter, a Highly Evasive RAT Loader. Retrieved September 13, 2023.
  2. Telefonica Snip3 December 2021 Open source
    Jornet, A. (2021, December 23). Snip3, an investigation into malware. Retrieved September 19, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.