How to get rid of SnakeBiteAgent RAT

Trojan

Also Known As: SnakeBiteAgent remote access trojan

Damage level:

Get free scan and check if your device is infected.

Remove it now

To use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

What kind of malware is SnakeBiteAgent?

SnakeBiteAgent is a Remote Access Trojan (RAT) discovered by ANY.RUN. It hands attackers control over an infected Windows computer and bundles password theft, banking fraud, cryptocurrency theft, and live surveillance into a single tool.

What makes this RAT unusual is that it does not stay completely invisible. After it settles on the machine, it can display a full-screen lock window that blocks access to the desktop and demands an unlock password, while the rest of its modules keep working in the background.

SnakeBiteAgent RAT detections on VirusTotal

SnakeBiteAgent RAT overview

The malware is built around a large command set - roughly 274 methods, none of them hidden behind obfuscation, which means every technique it supports is plainly named inside the file. Operators connect to the infected machine over a single channel and issue commands through it.

One of the core features is a hidden desktop. The RAT creates a second, invisible Windows desktop and starts a browser, Explorer, and Notepad inside it. The victim sees nothing on screen, yet the attacker can browse, open files, and click around as if sitting at the keyboard.

Alongside that, SnakeBiteAgent captures the real screen and streams the images back over the same connection. In practice, the operator watches everything the victim does and can also work on the machine unseen.

The lock screen shown after infiltration

After the infection is in place, the malware can throw up a black full-screen window titled SYSTEM LOCKED, stating that the computer has been locked and that all access is restricted. It asks for an unlock password and tells the victim to contact an email address, Supports@consultant.com, to obtain it.

The message is short and offers no explanation beyond that. There is no reason to write to the criminals behind it - paying or negotiating does not undo the infection, and the machine remains fully compromised regardless of whether the lock screen is removed.

Data theft, banking, and cryptocurrency

SnakeBiteAgent goes after saved credentials in Chromium-based browsers, including Chrome and Edge, pulling both stored logins and saved card data. It also reads the saved password file used by Firefox and collects credentials stored by Windows itself.

The RAT can inject commands into a running browser session and starts the browser off-screen with automation warnings disabled, so nothing looks out of place. It additionally runs a small web server on the machine itself, serving built-in fake Gmail, Microsoft, and Yahoo sign-in pages and recording each login attempt.

Banking is a clear priority. The malware watches for banking sites in the foreground and scans browsing history for recent visits, with a target list of 51 institutions, 31 of them in Southeast Asia. For cryptocurrency it monitors the clipboard and swaps copied wallet addresses and account numbers, and it hunts for wallet files on disk.

Surveillance capabilities

The malware includes a keylogger that records keystrokes to a local file, so passwords typed by hand end up captured even when they are not stored in a browser. Clipboard contents are logged as well.

It can also switch on the webcam and record from the microphone. Combined with screen capture, this gives operators a fairly complete picture of the victim, their surroundings, and their conversations.

Defense evasion and remote access

To stay alive on the system, SnakeBiteAgent tampers with Microsoft Defender through policy settings in the Windows Registry and attempts to stop the Defender service. It also abuses a Windows debugging feature to block chosen programs from launching, which is commonly used to keep security tools from starting.

Another trick is a loop that repeatedly re-shows the User Account Control prompt until the victim finally clicks Yes, granting the malware elevated rights.

For long-term access, the RAT silently installs legitimate remote support software such as AnyDesk and MeshCentral, opens a SOCKS proxy that routes attacker traffic through the victim's connection, scans the local network for other machines, and downloads and runs further payloads through PowerShell.

Threat Summary:
Name SnakeBiteAgent remote access trojan
Threat Type Remote Access Trojan (RAT), Information Stealer, Keylogger, Clipper
Detection Names Avast (Win32:MalwareX-gen [Spy]), Combo Cleaner (Gen:Variant.Ransom.Chaos.34), ESET-NOD32 (MSIL/Spy.Agent.FUY Trojan), Kaspersky (HEUR:Trojan.Win32.Generic), Microsoft (Trojan:MSIL/Stealer.HC!MTB), Full List (VirusTotal)
Symptoms Remote Access Trojans are designed to stealthily infiltrate the victim's computer and remain silent, and thus no particular symptoms are clearly visible on an infected machine. In this case, a full-screen window stating that the system is locked can be displayed.
Distribution methods Infected email attachments, malicious online advertisements, social engineering, software 'cracks'.
Damage Stolen passwords and banking information, identity theft, the victim's computer added to a botnet, additional infections, monetary loss, account hijacking.
Malware Removal (Windows)

To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner.

Download Combo Cleaner

To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Conclusion

SnakeBiteAgent is a serious threat that can drain bank accounts and cryptocurrency, hand over email and social media accounts, spy on the victim through the webcam and microphone, and open the door to further infections. The lock screen it displays is only the visible part of a much broader compromise, and the malware should be removed as soon as possible.

More examples of RATs are PackClient, E4del, and PINHOLE.

How did SnakeBiteAgent infiltrate my computer?

Threats of this class usually arrive through phishing emails and messages. The attachment or link is presented as an invoice, a delivery notice, a job offer, or a document that has to be reviewed, and opening it launches the trojan.

Pirated software is another common route. Illegal activation tools and cracks downloaded from torrent sites, file hosting pages, and shady forums frequently carry a RAT instead of, or alongside, the promised program. Fake software update prompts and deceptive ads lead to the same result.

Malware is also spread through fake download websites impersonating well-known applications, malicious advertising, infected USB drives, and vulnerabilities in outdated software. The files used range from executables and installers to archives, documents, scripts, and shortcut files.

How to avoid installation of malware?

Treat unexpected emails and messages with suspicion, especially when they push you to open an attachment or click a link. Check who the sender really is before doing anything. Download software only from official websites and app stores, and stay away from cracks, key generators, and pirated content, since those are a reliable way to end up infected.

Keep Windows and your installed programs updated through their official update tools, and do not trust update prompts that appear on random websites. Avoid intrusive ads and pop-ups, and do not allow notifications from pages you do not know. If you believe that your computer is already infected, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate infiltrated malware.

Lock screen displayed by SnakeBiteAgent after infiltration:

SnakeBiteAgent RAT lock screen displayed on an infected computer

Instant automatic malware removal:

Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:

DOWNLOAD Combo Cleaner

By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Quick menu:

How to remove malware manually?

Manual malware removal is a complicated task - usually it is best to allow antivirus or anti-malware programs to do this automatically. To remove this malware we recommend using Combo Cleaner Antivirus for Windows.

If you wish to remove malware manually, the first step is to identify the name of the malware that you are trying to remove. Here is an example of a suspicious program running on a user's computer:

Malware process running in the Task Manager

If you checked the list of programs running on your computer, for example, using task manager, and identified a program that looks suspicious, you should continue with these steps:

manual malware removal step 1Download a program called Autoruns. This program shows auto-start applications, Registry, and file system locations:

Autoruns application appearance

manual malware removal step 2Restart your computer into Safe Mode:

Windows XP and Windows 7 users: Start your computer in Safe Mode. Click Start, click Shut Down, click Restart, click OK. During your computer start process, press the F8 key on your keyboard multiple times until you see the Windows Advanced Option menu, and then select Safe Mode with Networking from the list.

Run Windows 7 or Windows XP in Safe Mode with Networking

Video showing how to start Windows 7 in "Safe Mode with Networking":

Windows 8 users: Start Windows 8 is Safe Mode with Networking - Go to Windows 8 Start Screen, type Advanced, in the search results select Settings. Click Advanced startup options, in the opened "General PC Settings" window, select Advanced startup.

Click the "Restart now" button. Your computer will now restart into the "Advanced Startup options menu". Click the "Troubleshoot" button, and then click the "Advanced options" button. In the advanced option screen, click "Startup settings".

Click the "Restart" button. Your PC will restart into the Startup Settings screen. Press F5 to boot in Safe Mode with Networking.

Run Windows 8 in Safe Mode with Networking

Video showing how to start Windows 8 in "Safe Mode with Networking":

Windows 10 users: Click the Windows logo and select the Power icon. In the opened menu click "Restart" while holding "Shift" button on your keyboard. In the "choose an option" window click on the "Troubleshoot", next select "Advanced options".

In the advanced options menu select "Startup Settings" and click on the "Restart" button. In the following window you should click the "F5" button on your keyboard. This will restart your operating system in safe mode with networking.

Run Windows 10 in Safe Mode with Networking

Video showing how to start Windows 10 in "Safe Mode with Networking":

manual malware removal step 3Extract the downloaded archive and run the Autoruns.exe file.

Extract Autoruns.zip archive and run Autoruns.exe application

manual malware removal step 4In the Autoruns application, click "Options" at the top and uncheck "Hide Empty Locations" and "Hide Windows Entries" options. After this procedure, click the "Refresh" icon.

Refresh Autoruns application results

manual malware removal step 5Check the list provided by the Autoruns application and locate the malware file that you want to eliminate.

You should write down its full path and name. Note that some malware hides process names under legitimate Windows process names. At this stage, it is very important to avoid removing system files. After you locate the suspicious program you wish to remove, right click your mouse over its name and choose "Delete".

Delete malware in Autoruns

After removing the malware through the Autoruns application (this ensures that the malware will not run automatically on the next system startup), you should search for the malware name on your computer. Be sure to enable hidden files and folders before proceeding. If you find the filename of the malware, be sure to remove it.

Search for malware and delete it

Reboot your computer in normal mode. Following these steps should remove any malware from your computer. Note that manual threat removal requires advanced computer skills. If you do not have these skills, leave malware removal to antivirus and anti-malware programs.

These steps might not work with advanced malware infections. As always it is best to prevent infection than try to remove malware later. To keep your computer safe, install the latest operating system updates and use antivirus software. To be sure your computer is free of malware infections, we recommend scanning it with Combo Cleaner Antivirus for Windows.

Frequently Asked Questions (FAQ)

My computer is infected with SnakeBiteAgent malware, should I format my storage device to get rid of it?

Formatting will certainly remove the infection, but it also erases every file stored on the drive. In most cases a scan with a reputable security tool such as Combo Cleaner is the better first step, and formatting should be kept as a last resort.

What are the biggest issues that SnakeBiteAgent malware can cause?

It can empty bank accounts and cryptocurrency wallets, hand over email and social media accounts, and record the victim through the webcam and microphone. On top of that, it allows attackers to install more malware and to use the infected computer as a stepping stone into other devices on the same network.

What is the purpose of SnakeBiteAgent malware?

Its purpose is to give attackers hidden remote control over the computer so they can steal credentials, commit banking and cryptocurrency fraud, watch the user, and run whatever commands or additional payloads they choose. The lock screen it displays is used to pressure the victim into contacting the criminals.

How did SnakeBiteAgent malware infiltrate my computer?

RATs of this kind typically reach victims through phishing emails with malicious attachments or links, pirated software and cracks, fake download and update pages, malicious advertising, and infected removable drives.

Will Combo Cleaner protect me from malware?

Yes. Combo Cleaner detects and removes almost all known malware infections. Keep in mind that advanced threats often bury themselves deep in the system, so running a full system scan rather than a quick one is important.

Share:

facebook
X (Twitter)
linkedin
copy link
Tomas Meskauskas

Tomas Meskauskas

Expert security researcher, professional malware analyst

I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate