Skip to content

Masslogger

MassLogger is a modular .NET information-stealing malware family sold in underground forums since 2020 and widely used in commodity credential-theft campaigns.

Profile source: Mallory opens in a new tab

Masslogger

Family profile

MassLogger is a modular .NET information-stealing malware family sold in underground forums since 2020 and widely used in commodity credential-theft campaigns. It is commonly characterized as an infostealer, spyware, and keylogger, with configurable modules that allow operators to tailor collection and exfiltration behavior. MassLogger primarily targets Windows systems and focuses on harvesting credentials and other sensitive data from web browsers, email clients, messaging applications, FTP clients, VPN software, and related desktop applications. Documented targets include Chromium-based browsers, Firefox, Outlook, Thunderbird, FoxMail, FileZilla, Discord, NordVPN, and other common user applications.

MassLogger is most frequently distributed through phishing and malspam, including archive attachments, Office documents with VBA macros, compiled HTML help files, and encoded VBScript files. Observed delivery chains have also used exploit-assisted Office documents, including CVE-2017-11882, as well as loader ecosystems such as ReZer0 and QuirkyLoader. Some campaigns used largely memory-resident or fileless execution chains involving JavaScript, PowerShell, .NET assembly loading, and process hollowing to reduce on-disk artifacts and evade detection.

Core capabilities include credential theft, keylogging, clipboard theft, screenshot capture, system and application reconnaissance, and exfiltration of collected data. Some variants also steal Discord tokens, gather host metadata such as operating system and installed security products, monitor foreground windows, search for and upload files, and compress stolen data before transmission. Exfiltration mechanisms observed across variants include FTP, SMTP, HTTP control panels, Telegram Bot API, and Discord-related abuse. Certain samples support optional modules that can be enabled or disabled by the operator.

MassLogger employs multiple defense-evasion techniques. Reported variants use heavy obfuscation, packing, encrypted configuration storage, anti-debugging, anti-VM and anti-sandbox checks, Windows Defender exclusion, and process injection or process hollowing into legitimate processes. Some newer variants reduce forensic artifacts by avoiding local log-file creation, while fileless variants have used the Windows Registry as a staging and persistence mechanism. Persistence has been observed via scheduled tasks and self-copying into user-profile locations.

MassLogger is associated with broad financially motivated cybercrime activity rather than a single threat actor. It has appeared in campaigns targeting both individuals and businesses across multiple regions, often alongside other commodity malware families such as Agent Tesla, FormBook, AsyncRAT, Remcos, Snake Keylogger, and XWorm. Its modular design, low barrier to entry, and flexible delivery chains have made it a persistent fixture in phishing-led credential-harvesting operations.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 28, 2026
Last activity
Sep 3, 2026
Feed role
C2 / Distribution
Host form
9 IP / 6 hostnames

Leading locations

  • US4
  • CH3
  • HK2
  • NL2
  • CA1
  • DE1
  • MX1
  • SG1

Leading providers

  • GLOBAL CONNECTIVITY SOLUTIONS LLP2
  • OVH SAS2
  • SKN Subnet & Telecom Ltd2
  • BlueVPS OU1
  • ChangLian Network Technology Co., Limited1
  • Cox Communications Inc.1

Infrastructure traits

  • Hosting 10

Samples

Recent associated samples

Exploited software

Vulnerabilities linked to Masslogger

1 CVEs

MITRE ATT&CK

Masslogger in ATT&CK

40 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.