Skip to content
Malware family

Masslogger

MassLogger is a .NET credential-stealing malware family and keylogger/spyware sold on underground forums since at least April 2020.

Profile source: Mallory opens in a new tab

Masslogger

Family profile

MassLogger is a .NET credential-stealing malware family and keylogger/spyware sold on underground forums since at least April 2020. It is commonly delivered through phishing campaigns, including business-themed emails with password-protected archives, encoded Visual Basic Script (VBE) files, ZIP/RAR attachments, and CHM-based chains, and it has also been observed delivered by loaders such as QuirkyLoader alongside other commodity malware including Agent Tesla, AsyncRAT, FormBook, Remcos RAT, Rhadamanthys Stealer, XWorm, Phantom Stealer, Dark Cloud, RedLine Stealer, and Snake Keylogger. Reported targeting includes Windows users in multiple European countries and phishing activity aligned with Indian financial and tax themes.

Observed capabilities include theft of credentials and data from Chromium-based browsers such as Chrome, Chromium, Edge, Opera, and Brave; Firefox and QQ Browser; email clients including Outlook, FoxMail, and Thunderbird; VPN software such as NordVPN; FTP clients such as FileZilla; messaging applications including Discord and Pidgin; keylogging; clipboard capture; and browser data theft. Some reporting specifically notes harvesting of Chrome login details, keystrokes, clipboard content, and upload of stolen files to a remote server. MassLogger has also been observed implementing Discord token stealing. In one Talos-analyzed campaign, keylogging capability existed but was disabled.

Several infection chains are described as heavily obfuscated and largely fileless after initial execution, relying on PowerShell, reflective .NET assembly loading, and process injection into msbuild.exe. One campaign used a CHM file embedded in a multi-volume RAR attachment, downloaded additional stages from compromised legitimate websites using .jpg-looking paths, loaded an obfuscated DLL named Waves.dll, and injected the final MassLogger payload into msbuild.exe. Another campaign used invoice-themed phishing leading to a ZIP archive containing a VBE script, with key components stored in the Windows Registry before delivering MassLogger. A separate January 7, 2026 infection chain used phishing emails with password-protected archives containing executables that delivered MassLogger.

MassLogger supports exfiltration over FTP, HTTP via a PHP-based control panel, and SMTP/email. In one analyzed sample, exfiltration occurred over FTP to med-star.gr and a related control panel was present at https://www.med-star.gr/panel/?/login; the internal assembly name was reported as service-med-star.gr and the sample version as 3.0.7563.31381. In the January 2026 email-delivered infection, post-infection traffic included requests to checkip.dyndns.org and reallyfreegeoip.org, exfiltration to cphost14.qhoster.net over encrypted SMTP on TCP 587, and stolen data sent to kingnovasend@mcnzxz.com. Hunting guidance in the provided content also associates MassLogger/VIPKeylogger infrastructure with direct IP-address URLs containing /txt/ or /htdocs/ folders and 13-18 character alphanumeric .exe filenames.

The malware is widely used in commodity credential-harvesting campaigns and has shown substantial prevalence growth in telemetry, with one source noting a 437% increase in malware share. The content also notes concurrent use with XWorm in January 2026, suggesting operators may run multiple infostealer campaigns simultaneously, using XWorm for persistent access and MassLogger for credential harvesting.

Observed infrastructure

Last seven days

First activity
Jul 20, 2026
Last activity
Jul 21, 2026
Feed role
Distribution
Host form
2 IP / 2 hostnames

Leading locations

  • CH2
  • HK1
  • SG1

Leading providers

  • DEDIK SERVICES LIMITED1
  • OVH SAS1
  • SKN Subnet & Telecom Ltd1
  • Tele Asia Limited1

Infrastructure traits

  • Hosting 3

Samples

Recent associated samples

MITRE ATT&CK

Masslogger in ATT&CK

9 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.