Last seven days
- First activity
- Jul 31, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 5 IP / 6 hostnames
VIPKeylogger is a Windows credential-stealing malware family commonly distributed through malspam and phishing campaigns that use business-themed lures such as orders, requests, quotes, invoices, shipping notices, payments, and offers.
Profile source: Mallory opens in a new tabVIPKeylogger
VIPKeylogger is a Windows credential-stealing malware family commonly distributed through malspam and phishing campaigns that use business-themed lures such as orders, requests, quotes, invoices, shipping notices, payments, and offers. It has been observed in multi-stage infection chains using script-based droppers and loaders including VBScript, JavaScript, PowerShell, AutoIT, NSIS-wrapped payloads, shellcode loaders, and GuLoader-style delivery. Reported campaigns have used techniques such as hidden PowerShell execution via WMI, reflective in-memory loading of .NET assemblies, steganographic payload staging, and process injection or hollowing into legitimate Windows binaries to evade detection.
VIPKeylogger is associated with password-stealing activity and has been described as a variant or rebrand of SnakeKeylogger, also known as 404 Keylogger, in some campaigns. Observed functionality includes theft of credentials and other victim information, keylogging, reconnaissance of victim systems and external network identity, persistence through startup items and scheduled tasks, and exfiltration of collected data. Exfiltration channels documented for VIPKeylogger include SMTP and Telegram, with some campaigns using dual-channel exfiltration for redundancy and real-time operator notification.
The malware has been repeatedly observed targeting organizations and users through opportunistic phishing, including campaigns aimed at Italian businesses and other business users with localized lures, as well as tax-themed social engineering in Vietnam. Delivery chains have included archive attachments, script files, and disguised executables. In analyzed intrusions, VIPKeylogger has used defense-evasion measures such as obfuscation, anti-analysis checks, encrypted or XOR-encoded payload stages, and process injection into legitimate Windows processes. Overall, VIPKeylogger is best characterized as a commodity Windows infostealer/keylogger used in financially motivated phishing operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
0f78a658b60f0879acccf0933d9ae8a5d2c188e9f16b8e6f7b01bd0cc9b5c4e1 27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e 0466815759a6b6ab8ead1eecfa7e55ddf3463f48a38566088ca46e8d280c3d6f 25499db3dbb4b22b4d5c22500d258732638cb19cd96f29b6eda218c3c49bd319 36c1b04627334fc449ad934a57898e230b52df637baa8d463cdcc536fa564563 38f26c2517e8206ed16b0e894f7798bc08e524cb446a5d4ebb4066dc749d2e09 c7dd2a3958495052756eee929c6bc0ea3801f40b286eaa9b1d1dfffde0eeddb5 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.