Skip to content

VIPKeylogger

VIPKeylogger is a Windows infostealer and keylogger that is widely assessed as a variant or rebrand of SnakeKeylogger, also known as 404 Keylogger.

Profile source: Mallory opens in a new tab

VIPKeylogger

Family profile

VIPKeylogger is a Windows infostealer and keylogger that is widely assessed as a variant or rebrand of SnakeKeylogger, also known as 404 Keylogger. It is used in credential-theft operations and has been observed in broad malspam and phishing campaigns, including business-themed lures such as orders, requests, quotes, invoices, offers, payments, and shipping notices, as well as brand-themed delivery lures and tax-authority impersonation. Activity has been repeatedly observed against organizations and users in Italy and in wider international campaigns.

The malware is designed to harvest sensitive information from infected systems. Reported capabilities include theft of credentials and other victim data, keylogging, and exfiltration of collected information to attacker-controlled infrastructure. Multiple analyses associate VIPKeylogger with dual or alternate exfiltration channels, especially Telegram Bot API and SMTP, and some campaigns place it within broader credential-theft ecosystems that also use FTP or other channels for related malware families. VIPKeylogger has also been observed sending victim notifications through Telegram.

Observed delivery chains show substantial use of script-based loaders and multi-stage execution. Campaigns have used phishing emails carrying archives or script attachments, including VBS and JavaScript droppers, followed by PowerShell stages, reflective .NET loading, AutoIT-based loaders, shellcode execution, and process injection or hollowing into legitimate Windows binaries. Some samples established persistence through Run-key entries, startup scripts, or scheduled tasks, and some employed anti-analysis or obfuscation techniques to hinder detection.

VIPKeylogger appears in commodity cybercrime operations rather than exclusively in state-linked activity. It is commonly clustered with other credential-stealing malware such as AgentTesla, FormBook, Remcos, PureLogs, and PhantomStealer in malspam reporting, and has been advertised alongside SnakeKeylogger by the same operator ecosystem. Its role in stealing credentials makes it relevant to financially motivated intrusion activity and to downstream initial-access abuse.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
9 IP / 12 hostnames

Leading locations

  • TR4
  • US4
  • DE2
  • HK2
  • CH1
  • GB1
  • HU1
  • LU1
  • MY1
  • NL1
  • RO1
  • SG1

Leading providers

  • Hetzner Online GmbH2
  • OVH SAS2
  • ChangLian Network Technology Co., Limited1
  • CIZGI TELEKOMUNIKASYON ANONIM SIRKETI1
  • Cox Communications Inc.1
  • DEDIK SERVICES LIMITED1

Infrastructure traits

  • Hosting 17

Samples

Recent associated samples

MITRE ATT&CK

VIPKeylogger in ATT&CK

41 distinct techniques

Reporting

Research mentioning VIPKeylogger

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.