C2 Implant 'SnappyClient' Targets Crypto Wallets

2026-03-19T02:51:42Zcd35ea6691cc36c7f5f994006944925956925f4d55d8d98ea086df39eaa04359
BlackSantaC2 implantClaudeEDR bypassGitHub Action compromiseGlassWormINC ransomwareMicrosoft Patch TuesdaySideWinderWarlockcredential theftcrypto walletsespionageexploit kitiOS zero-dayinfostealerslivechat social engineeringmalvertisingmalware evolutionphishingprompt injectionransomwaresupply chain compromisetag poisoningvulnerability exploitation

What happened

This feed highlights a surge in diverse, high-impact threats across mobile, cloud, and supply-chain vectors. Notable items include a new C2 implant called 'SnappyClient' targeting crypto wallets; the 'DarkSword' iOS exploit chain leveraging multiple zero-days against users in Saudi Arabia, Turkey, Malaysia and Ukraine; a prompt-injection and chaining campaign dubbed 'Claudy Day' that threatens Claude users and enterprise networks; expansion of the SideWinder espionage campaign across Southeast Asia; and multiple supply-chain incidents (Xygeni GitHub Action tag-poison compromise, GlassWorm back

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
cd35ea6691cc36c7f5f994006944925956925f4d55d8d98ea086df39eaa04359
Enrichment time
2026-03-19T02:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · C2 Implant 'SnappyClient' Targets Crypto Wallets · Baitaphish