Last seven days
- First activity
- Aug 28, 2026
- Last activity
- Sep 3, 2026
- Feed role
- C2 / Distribution
- Host form
- 9 IP / 6 hostnames
MassLogger is a modular .NET information-stealing malware family sold in underground forums since 2020 and widely used in commodity credential-theft campaigns.
Profile source: Mallory opens in a new tabMasslogger
MassLogger is a modular .NET information-stealing malware family sold in underground forums since 2020 and widely used in commodity credential-theft campaigns. It is commonly characterized as an infostealer, spyware, and keylogger, with configurable modules that allow operators to tailor collection and exfiltration behavior. MassLogger primarily targets Windows systems and focuses on harvesting credentials and other sensitive data from web browsers, email clients, messaging applications, FTP clients, VPN software, and related desktop applications. Documented targets include Chromium-based browsers, Firefox, Outlook, Thunderbird, FoxMail, FileZilla, Discord, NordVPN, and other common user applications.
MassLogger is most frequently distributed through phishing and malspam, including archive attachments, Office documents with VBA macros, compiled HTML help files, and encoded VBScript files. Observed delivery chains have also used exploit-assisted Office documents, including CVE-2017-11882, as well as loader ecosystems such as ReZer0 and QuirkyLoader. Some campaigns used largely memory-resident or fileless execution chains involving JavaScript, PowerShell, .NET assembly loading, and process hollowing to reduce on-disk artifacts and evade detection.
Core capabilities include credential theft, keylogging, clipboard theft, screenshot capture, system and application reconnaissance, and exfiltration of collected data. Some variants also steal Discord tokens, gather host metadata such as operating system and installed security products, monitor foreground windows, search for and upload files, and compress stolen data before transmission. Exfiltration mechanisms observed across variants include FTP, SMTP, HTTP control panels, Telegram Bot API, and Discord-related abuse. Certain samples support optional modules that can be enabled or disabled by the operator.
MassLogger employs multiple defense-evasion techniques. Reported variants use heavy obfuscation, packing, encrypted configuration storage, anti-debugging, anti-VM and anti-sandbox checks, Windows Defender exclusion, and process injection or process hollowing into legitimate processes. Some newer variants reduce forensic artifacts by avoiding local log-file creation, while fileless variants have used the Windows Registry as a staging and persistence mechanism. Persistence has been observed via scheduled tasks and self-copying into user-profile locations.
MassLogger is associated with broad financially motivated cybercrime activity rather than a single threat actor. It has appeared in campaigns targeting both individuals and businesses across multiple regions, often alongside other commodity malware families such as Agent Tesla, FormBook, AsyncRAT, Remcos, Snake Keylogger, and XWorm. Its modular design, low barrier to entry, and flexible delivery chains have made it a persistent fixture in phishing-led credential-harvesting operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
25b5c7f85cae8d847cf73df5086b1c05b5e200460a7c2d2cc04d89273208f297 51bc558d6ea1e276262e12aed5c84086d4f2b8ec7b106609b36e3f9647eb747f afa95f8089310841b669215cc5b699fe05c7560dc2e180387e60a129a91cdd7b e154e9bb0cff026e615b2442d40a5cd2e462b39b73743bed39c2124fd5bda519 e76d28e648a606ad7e0427b533845a49cf240f44c1ad03ed5ead35cff33d6537 e7c005c6be3e95413eb5db6b6116ce06cac9b63215e1ebc9a603f8bc678622e6 7108c0f376edbe09cc2a883cb4b0092f2b1a0f5517a042e01a02775049093893 0f78a658b60f0879acccf0933d9ae8a5d2c188e9f16b8e6f7b01bd0cc9b5c4e1 27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.