Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 9 IP / 12 hostnames
VIPKeylogger is a Windows infostealer and keylogger that is widely assessed as a variant or rebrand of SnakeKeylogger, also known as 404 Keylogger.
Profile source: Mallory opens in a new tabVIPKeylogger
VIPKeylogger is a Windows infostealer and keylogger that is widely assessed as a variant or rebrand of SnakeKeylogger, also known as 404 Keylogger. It is used in credential-theft operations and has been observed in broad malspam and phishing campaigns, including business-themed lures such as orders, requests, quotes, invoices, offers, payments, and shipping notices, as well as brand-themed delivery lures and tax-authority impersonation. Activity has been repeatedly observed against organizations and users in Italy and in wider international campaigns.
The malware is designed to harvest sensitive information from infected systems. Reported capabilities include theft of credentials and other victim data, keylogging, and exfiltration of collected information to attacker-controlled infrastructure. Multiple analyses associate VIPKeylogger with dual or alternate exfiltration channels, especially Telegram Bot API and SMTP, and some campaigns place it within broader credential-theft ecosystems that also use FTP or other channels for related malware families. VIPKeylogger has also been observed sending victim notifications through Telegram.
Observed delivery chains show substantial use of script-based loaders and multi-stage execution. Campaigns have used phishing emails carrying archives or script attachments, including VBS and JavaScript droppers, followed by PowerShell stages, reflective .NET loading, AutoIT-based loaders, shellcode execution, and process injection or hollowing into legitimate Windows binaries. Some samples established persistence through Run-key entries, startup scripts, or scheduled tasks, and some employed anti-analysis or obfuscation techniques to hinder detection.
VIPKeylogger appears in commodity cybercrime operations rather than exclusively in state-linked activity. It is commonly clustered with other credential-stealing malware such as AgentTesla, FormBook, Remcos, PureLogs, and PhantomStealer in malspam reporting, and has been advertised alongside SnakeKeylogger by the same operator ecosystem. Its role in stealing credentials makes it relevant to financially motivated intrusion activity and to downstream initial-access abuse.
C2 tracking
Derp observations, rolling seven-day window
Samples
3d8eb5e65e545ab963c5c05b12c79c68f1b43ef0f7da69ddf25b476cdeff847c a1998deb197f8e5057893ecce3a983dcb46d8bc5b597a29ddde9182f24d0d801 ae90d92c84a667b337673aef573250aaad80b134b5d46f60fa399ed1920f8b12 e4a965c21b5070d2ce805eb6a82e50dd5c5e1912d772d1be901c9b136e532857 eb634822849f7fddda37cbe6cb600a6502043e6c0bc78453620b16645725d92c fc70d38d68e96354251ea39f6b8bf6489388773c056f111835acb708449b2006 1c6e53e93260fcb3d6a2f0ff0a5ec8e40434b6346d1e08c884902be30c91d05c 7ce8b2febb5c96f2551fffc5865ea75028146a1dcd67279166488bd3f369ec48 a4d6d447eda000a22a4c17a627d8657c0e79774ab420a3c26d126eb8dc4ebe5a 7aa7464a9d1299d1a5c07c1b793b4a54d9f6ac7c244bf01af4ac6d5ea581aeaa MITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.