C2 Implant 'SnappyClient' Targets Crypto Wallets
2026-03-19T02:51:42Z•cd35ea6691cc36c7f5f994006944925956925f4d55d8d98ea086df39eaa04359
BlackSantaC2 implantClaudeEDR bypassGitHub Action compromiseGlassWormINC ransomwareMicrosoft Patch TuesdaySideWinderWarlockcredential theftcrypto walletsespionageexploit kitiOS zero-dayinfostealerslivechat social engineeringmalvertisingmalware evolutionphishingprompt injectionransomwaresupply chain compromisetag poisoningvulnerability exploitation
What happened
This feed highlights a surge in diverse, high-impact threats across mobile, cloud, and supply-chain vectors. Notable items include a new C2 implant called 'SnappyClient' targeting crypto wallets; the 'DarkSword' iOS exploit chain leveraging multiple zero-days against users in Saudi Arabia, Turkey, Malaysia and Ukraine; a prompt-injection and chaining campaign dubbed 'Claudy Day' that threatens Claude users and enterprise networks; expansion of the SideWinder espionage campaign across Southeast Asia; and multiple supply-chain incidents (Xygeni GitHub Action tag-poison compromise, GlassWorm back
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- cd35ea6691cc36c7f5f994006944925956925f4d55d8d98ea086df39eaa04359
- Enrichment time
- 2026-03-19T02:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.