MassLogger is a .NET credential-stealing malware family and keylogger/spyware sold on underground forums since at least April 2020. It is commonly delivered through phishing campaigns, including business-themed emails with password-protected archives, encoded Visual Basic Script (VBE) files, ZIP/RAR attachments, and CHM-based chains, and it has also been observed delivered by loaders such as QuirkyLoader alongside other commodity malware including Agent Tesla, AsyncRAT, FormBook, Remcos RAT, Rhadamanthys Stealer, XWorm, Phantom Stealer, Dark Cloud, RedLine Stealer, and Snake Keylogger. Reported targeting includes Windows users in multiple European countries and phishing activity aligned with Indian financial and tax themes.
Observed capabilities include theft of credentials and data from Chromium-based browsers such as Chrome, Chromium, Edge, Opera, and Brave; Firefox and QQ Browser; email clients including Outlook, FoxMail, and Thunderbird; VPN software such as NordVPN; FTP clients such as FileZilla; messaging applications including Discord and Pidgin; keylogging; clipboard capture; and browser data theft. Some reporting specifically notes harvesting of Chrome login details, keystrokes, clipboard content, and upload of stolen files to a remote server. MassLogger has also been observed implementing Discord token stealing. In one Talos-analyzed campaign, keylogging capability existed but was disabled.
Several infection chains are described as heavily obfuscated and largely fileless after initial execution, relying on PowerShell, reflective .NET assembly loading, and process injection into msbuild.exe. One campaign used a CHM file embedded in a multi-volume RAR attachment, downloaded additional stages from compromised legitimate websites using .jpg-looking paths, loaded an obfuscated DLL named Waves.dll, and injected the final MassLogger payload into msbuild.exe. Another campaign used invoice-themed phishing leading to a ZIP archive containing a VBE script, with key components stored in the Windows Registry before delivering MassLogger. A separate January 7, 2026 infection chain used phishing emails with password-protected archives containing executables that delivered MassLogger.
MassLogger supports exfiltration over FTP, HTTP via a PHP-based control panel, and SMTP/email. In one analyzed sample, exfiltration occurred over FTP to med-star.gr and a related control panel was present at https://www.med-star.gr/panel/?/login; the internal assembly name was reported as service-med-star.gr and the sample version as 3.0.7563.31381. In the January 2026 email-delivered infection, post-infection traffic included requests to checkip.dyndns.org and reallyfreegeoip.org, exfiltration to cphost14.qhoster.net over encrypted SMTP on TCP 587, and stolen data sent to kingnovasend@mcnzxz.com. Hunting guidance in the provided content also associates MassLogger/VIPKeylogger infrastructure with direct IP-address URLs containing /txt/ or /htdocs/ folders and 13-18 character alphanumeric .exe filenames.
The malware is widely used in commodity credential-harvesting campaigns and has shown substantial prevalence growth in telemetry, with one source noting a 437% increase in malware share. The content also notes concurrent use with XWorm in January 2026, suggesting operators may run multiple infostealer campaigns simultaneously, using XWorm for persistent access and MassLogger for credential harvesting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Phishing emails remain the dominant delivery method, accounting for 61% of threats that reached endpoints. One campaign used realistic invoice-themed emails to trick recipients into opening SVG attachments.
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Keylogging and credential-stealing malware family observed as an alternate payload from the same infrastructure.
MassLogger is an infostealer used alongside XWorm in the same infrastructure, specifically for credential harvesting.
Credential theft/keylogging malware delivered as a secondary payload (here, via QuirkyLoader).
Credential stealer referenced as a QuirkyLoader-delivered payload; no further details in excerpt.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.