MassLogger is a modular .NET information-stealing malware family sold in underground forums since 2020 and widely used in commodity credential-theft campaigns. It is commonly characterized as an infostealer, spyware, and keylogger, with configurable modules that allow operators to tailor collection and exfiltration behavior. MassLogger primarily targets Windows systems and focuses on harvesting credentials and other sensitive data from web browsers, email clients, messaging applications, FTP clients, VPN software, and related desktop applications. Documented targets include Chromium-based browsers, Firefox, Outlook, Thunderbird, FoxMail, FileZilla, Discord, NordVPN, and other common user applications.
MassLogger is most frequently distributed through phishing and malspam, including archive attachments, Office documents with VBA macros, compiled HTML help files, and encoded VBScript files. Observed delivery chains have also used exploit-assisted Office documents, including CVE-2017-11882, as well as loader ecosystems such as ReZer0 and QuirkyLoader. Some campaigns used largely memory-resident or fileless execution chains involving JavaScript, PowerShell, .NET assembly loading, and process hollowing to reduce on-disk artifacts and evade detection.
Core capabilities include credential theft, keylogging, clipboard theft, screenshot capture, system and application reconnaissance, and exfiltration of collected data. Some variants also steal Discord tokens, gather host metadata such as operating system and installed security products, monitor foreground windows, search for and upload files, and compress stolen data before transmission. Exfiltration mechanisms observed across variants include FTP, SMTP, HTTP control panels, Telegram Bot API, and Discord-related abuse. Certain samples support optional modules that can be enabled or disabled by the operator.
MassLogger employs multiple defense-evasion techniques. Reported variants use heavy obfuscation, packing, encrypted configuration storage, anti-debugging, anti-VM and anti-sandbox checks, Windows Defender exclusion, and process injection or process hollowing into legitimate processes. Some newer variants reduce forensic artifacts by avoiding local log-file creation, while fileless variants have used the Windows Registry as a staging and persistence mechanism. Persistence has been observed via scheduled tasks and self-copying into user-profile locations.
MassLogger is associated with broad financially motivated cybercrime activity rather than a single threat actor. It has appeared in campaigns targeting both individuals and businesses across multiple regions, often alongside other commodity malware families such as Agent Tesla, FormBook, AsyncRAT, Remcos, Snake Keylogger, and XWorm. Its modular design, low barrier to entry, and flexible delivery chains have made it a persistent fixture in phishing-led credential-harvesting operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In some cases, threat actors have used office document file as initial infection vector with VBA macro and equation editor exploit... containing 2 VBScripts and 1 file of CVE-2017-11882 exploit... The excel sheet containing stack-based buffer overflow editor exploit of the equation editor renames and executes VB Scripts using WinExec api post-exploitation. | We have been dealing with a new spyware for the past two months, named MassLogger. This advanced keylogger and spyware are distributed via MalSpam attachments...
31 distinct techniques documented for this family, organized by ATT&CK tactic.
USB Spread, it uses an open-source code of LimeUSB... It is used to infect files stored on the USB drive.
After that, to stay persistent in the system, it creates an entry in task scheduler.
These threats demonstrate several techniques of the MITRE ATT&CK framework, most notably... T1059.001... The second stage is a PowerShell script that eventually deobfuscates into a downloader and downloads and loads the main PowerShell loader.
In some cases, threat actors have used office document file as initial infection vector with VBA macro and equation editor exploit. | The first stream oleObject1.bin is a VB script file contains renamer code and after which it executes VBS file using Wscript.
After that, to stay persistent in the system, it creates an entry in task scheduler.
OleObject2.bin stream is also a VB script which is highly obfuscated... The Lazarus.exe gets dumped which is highly obfuscated .NET file... All function and class names are modified to random/obfuscated string.
This report summarizes the distribution channels, number of Infostealers, number of detections, and target companies that were disguised as Infostealers collected during the month of July 2026.
The sample we investigated starts itself in a new process, allocates executable memory and injects the mentioned routine into the newly created process via Process Injection.
Following image shows the use of the self-hollowing technique to do its further activity.
These threats demonstrate several techniques of the MITRE ATT&CK framework, most notably... T1140 — Deobfuscate/Decode Files or Information... Every stage of the infection is obfuscated to avoid detection using simple signatures.
MassLogger can steal account credentials, screenshots, keylogging data, and clipboard information stored in browsers and on clients.
A Discord access token is a unique alphanumeric string that is generated for each user and is essentially the "key" to that user's account. If another party were to have access to this token it would allow them to have full control over that account.
MassLogger can steal account credentials, screenshots, keylogging data, and clipboard information stored in browsers and on clients.
These threats demonstrate several techniques of the MITRE ATT&CK framework, most notably... T1555.003 — Credentials from Web Browsers... The main payload is a variant of the Masslogger trojan designed to retrieve and exfiltrate user credentials from a variety of sources.
also gets running process information. MassLogger also stores a running process windows name in its log file.
It starts collecting system information like name of the system, Windows version, CPU, GPU, AV installed, Public IP... also gets running process information.
MassLogger can steal account credentials, screenshots, keylogging data, and clipboard information stored in browsers and on clients.
MassLogger can steal account credentials, screenshots, keylogging data, and clipboard information stored in browsers and on clients.
MassLogger can steal account credentials, screenshots, keylogging data, and clipboard information stored in browsers and on clients.
However, any data can be sent to a webhook, allowing for data exfiltration.
the variant we investigated tried to send the results over SMTP to the c2 server. We also identified that MassLogger can atleast be configured to transfer the logging results via FTP to its control server.
These threats demonstrate several techniques of the MITRE ATT&CK framework, most notably... T1048.003 — Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol... The exfiltration of data takes place over one or more of these channels: FTP... HTTP... SMTP.
197 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MassLogger can steal account credentials, screenshots, keylogging data, and clipboard information stored in browsers and on clients.
Keylogging and credential-stealing malware family observed as an alternate payload from the same infrastructure.
Alternate payload family seen in related samples from the same campaign infrastructure; also found in metadata-linked samples alongside Remcos.
MassLogger is an infostealer used alongside XWorm in the same infrastructure, specifically for credential harvesting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.