Last seven days
- First activity
- Jul 20, 2026
- Last activity
- Jul 21, 2026
- Feed role
- Distribution
- Host form
- 2 IP / 2 hostnames
MassLogger is a .NET credential-stealing malware family and keylogger/spyware sold on underground forums since at least April 2020.
Profile source: Mallory opens in a new tabMasslogger
MassLogger is a .NET credential-stealing malware family and keylogger/spyware sold on underground forums since at least April 2020. It is commonly delivered through phishing campaigns, including business-themed emails with password-protected archives, encoded Visual Basic Script (VBE) files, ZIP/RAR attachments, and CHM-based chains, and it has also been observed delivered by loaders such as QuirkyLoader alongside other commodity malware including Agent Tesla, AsyncRAT, FormBook, Remcos RAT, Rhadamanthys Stealer, XWorm, Phantom Stealer, Dark Cloud, RedLine Stealer, and Snake Keylogger. Reported targeting includes Windows users in multiple European countries and phishing activity aligned with Indian financial and tax themes.
Observed capabilities include theft of credentials and data from Chromium-based browsers such as Chrome, Chromium, Edge, Opera, and Brave; Firefox and QQ Browser; email clients including Outlook, FoxMail, and Thunderbird; VPN software such as NordVPN; FTP clients such as FileZilla; messaging applications including Discord and Pidgin; keylogging; clipboard capture; and browser data theft. Some reporting specifically notes harvesting of Chrome login details, keystrokes, clipboard content, and upload of stolen files to a remote server. MassLogger has also been observed implementing Discord token stealing. In one Talos-analyzed campaign, keylogging capability existed but was disabled.
Several infection chains are described as heavily obfuscated and largely fileless after initial execution, relying on PowerShell, reflective .NET assembly loading, and process injection into msbuild.exe. One campaign used a CHM file embedded in a multi-volume RAR attachment, downloaded additional stages from compromised legitimate websites using .jpg-looking paths, loaded an obfuscated DLL named Waves.dll, and injected the final MassLogger payload into msbuild.exe. Another campaign used invoice-themed phishing leading to a ZIP archive containing a VBE script, with key components stored in the Windows Registry before delivering MassLogger. A separate January 7, 2026 infection chain used phishing emails with password-protected archives containing executables that delivered MassLogger.
MassLogger supports exfiltration over FTP, HTTP via a PHP-based control panel, and SMTP/email. In one analyzed sample, exfiltration occurred over FTP to med-star.gr and a related control panel was present at https://www.med-star.gr/panel/?/login; the internal assembly name was reported as service-med-star.gr and the sample version as 3.0.7563.31381. In the January 2026 email-delivered infection, post-infection traffic included requests to checkip.dyndns.org and reallyfreegeoip.org, exfiltration to cphost14.qhoster.net over encrypted SMTP on TCP 587, and stolen data sent to kingnovasend@mcnzxz.com. Hunting guidance in the provided content also associates MassLogger/VIPKeylogger infrastructure with direct IP-address URLs containing /txt/ or /htdocs/ folders and 13-18 character alphanumeric .exe filenames.
The malware is widely used in commodity credential-harvesting campaigns and has shown substantial prevalence growth in telemetry, with one source noting a 437% increase in malware share. The content also notes concurrent use with XWorm in January 2026, suggesting operators may run multiple infostealer campaigns simultaneously, using XWorm for persistent access and MassLogger for credential harvesting.
Samples
7ed8a5fe5a9c7f9a15198e6bf76128657ac544113775c95d3aebafe4888e5110 bc7493c7253c423bba4e1bd4790fb1a2c6517e7424d8553cdf4a96552a99a91f 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 5eb4973ce58ca8d691309fe57959dfb2f43d9f9cb4e094b23b6aa0ff173bb12a c89dc886211fa450eb09952143e6a289264abfcfe6d4429a4d0259179759fcd4 ca62e31191f9abcbf923e723d363b1841ac7b20a6ca9da9345e7d4922ecb8fe3 4f88fe008499703f828a96ea628d4daa58c4cfc6999390ce7777cca5a0ae78da MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.