MassLogger is a Windows-based .NET credential-stealing malware family commonly described as an infostealer and, in some campaigns, a keylogger-capable spyware trojan. Active since at least 2020 and sold on underground forums, it is frequently used in commodity cybercrime operations focused on harvesting credentials and other user data from browsers, email clients, messaging applications, VPN software, FTP clients, and related desktop applications. Reported targets include Chromium-based browsers, Firefox-derived browsers, Microsoft Outlook, Thunderbird, FoxMail, FileZilla, Discord, NordVPN, and other commonly used client software.
Its core functionality centers on credential theft and data exfiltration. Documented variants can capture browser-stored login data, collect clipboard contents, and exfiltrate stolen information over protocols including FTP, SMTP, and HTTP-based panels. MassLogger also has keylogging capability, although some observed campaigns disabled that feature in configuration. Additional reporting indicates some variants have implemented Discord token theft. In-memory execution and reflective loading have been observed in multiple campaigns, including loaders that reconstruct and execute .NET assemblies in memory and inject the final payload into legitimate Windows processes such as msbuild.exe to reduce detection.
MassLogger is commonly delivered through phishing and malspam campaigns using business-themed lures such as invoices, quotations, and financial documents. Observed delivery chains include password-protected archives, multi-volume compressed attachments, compiled HTML Help files, Visual Basic Encoded scripts, and archive-contained executables. PowerShell-heavy, largely fileless chains have also been documented, with obfuscated scripts downloading or reconstructing later stages in memory. The malware is additionally distributed by third-party loaders and malware delivery services, including QuirkyLoader, and has appeared alongside other commodity malware families such as Agent Tesla, AsyncRAT, Formbook, Remcos, Rhadamanthys, Snake Keylogger, XWorm, RedLine, and Phantom Stealer, indicating shared delivery infrastructure and loader-as-a-service style operations.
MassLogger primarily targets Windows environments and is prevalent in broad financially motivated campaigns rather than tightly scoped espionage operations. Geographic targeting in observed campaigns has included multiple European countries, and invoice- or tax-themed lures have also been used against organizations in other regions. Its continued use reflects the enduring effectiveness of low-cost credential theft malware combined with evasive, memory-resident loaders and socially engineered email delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Phishing emails remain the dominant delivery method, accounting for 61% of threats that reached endpoints. One campaign used realistic invoice-themed emails to trick recipients into opening SVG attachments.
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Keylogging and credential-stealing malware family observed as an alternate payload from the same infrastructure.
MassLogger is an infostealer used alongside XWorm in the same infrastructure, specifically for credential harvesting.
Credential theft/keylogging malware delivered as a secondary payload (here, via QuirkyLoader).
Credential stealer referenced as a QuirkyLoader-delivered payload; no further details in excerpt.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.