Netskope Threat Labs

Snojan

ATP Sandbox Adv. Heuristics

Snojan is a detection name for trojan malware that establishes persistence and steals data on infected systems. Detections under this name indicate an implant that survived reboots and collected files or credentials for its operators, and crews typically deliver it through phishing and loader chains. Analysts should trace the infection chain and remove all persistence mechanisms before returning a system to service.

First seen
March 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Downloader.Snojan
ByteCode-MSIL.Infostealer.Snojan
Win32.Infostealer.Snojan
Win64.Downloader.Snojan
Win64.Infostealer.Snojan