Skip to content

VIPKeylogger

VIPKeylogger is a Windows credential-stealing malware family commonly distributed through malspam and phishing campaigns that use business-themed lures such as orders, requests, quotes, invoices, shipping notices, payments, and offers.

Profile source: Mallory opens in a new tab

VIPKeylogger

Family profile

VIPKeylogger is a Windows credential-stealing malware family commonly distributed through malspam and phishing campaigns that use business-themed lures such as orders, requests, quotes, invoices, shipping notices, payments, and offers. It has been observed in multi-stage infection chains using script-based droppers and loaders including VBScript, JavaScript, PowerShell, AutoIT, NSIS-wrapped payloads, shellcode loaders, and GuLoader-style delivery. Reported campaigns have used techniques such as hidden PowerShell execution via WMI, reflective in-memory loading of .NET assemblies, steganographic payload staging, and process injection or hollowing into legitimate Windows binaries to evade detection.

VIPKeylogger is associated with password-stealing activity and has been described as a variant or rebrand of SnakeKeylogger, also known as 404 Keylogger, in some campaigns. Observed functionality includes theft of credentials and other victim information, keylogging, reconnaissance of victim systems and external network identity, persistence through startup items and scheduled tasks, and exfiltration of collected data. Exfiltration channels documented for VIPKeylogger include SMTP and Telegram, with some campaigns using dual-channel exfiltration for redundancy and real-time operator notification.

The malware has been repeatedly observed targeting organizations and users through opportunistic phishing, including campaigns aimed at Italian businesses and other business users with localized lures, as well as tax-themed social engineering in Vietnam. Delivery chains have included archive attachments, script files, and disguised executables. In analyzed intrusions, VIPKeylogger has used defense-evasion measures such as obfuscation, anti-analysis checks, encrypted or XOR-encoded payload stages, and process injection into legitimate Windows processes. Overall, VIPKeylogger is best characterized as a commodity Windows infostealer/keylogger used in financially motivated phishing operations.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 31, 2026
Last activity
Aug 6, 2026
Feed role
C2 / Distribution
Host form
5 IP / 6 hostnames

Leading locations

  • US5
  • CA1
  • ES1
  • GB1
  • HK1
  • NL1
  • RO1

Leading providers

  • ChangLian Network Technology Co., Limited1
  • Cloudflare, Inc.1
  • Cox Communications Inc.1
  • Google LLC1
  • Host Sailor Ltd1
  • IONOS SE1

Infrastructure traits

  • Hosting 10
  • Anycast 1

Samples

Recent associated samples

MITRE ATT&CK

VIPKeylogger in ATT&CK

40 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.