VIP Keylogger is a .NET-based information stealer and keylogger distributed primarily through phishing and impersonation-themed campaigns. Reported delivery chains include malicious business-themed emails carrying ZIP archives with executables disguised as documents, as well as heavily obfuscated .vbs, .js, and .bat script loaders. Observed loader behavior includes self-copying batch scripts, multi-stage PowerShell reconstruction, use of environment variables to stage code, Base64/AES/GZIP decoding, and in some campaigns steganographic retrieval of payload components from PNG image files. One analyzed chain used two .NET executables, where the second stage disabled or patched ETW telemetry, modified memory protections with VirtualProtect, set Microsoft Defender exclusions, decrypted and decompressed an embedded resource, and recovered an additional .NET payload identified in reporting as Remington.exe. Reported defense-evasion behavior also includes weakening AMSI and event logging, hidden-window execution, abuse of trusted .NET/Windows binaries, injection into aspnet_compiler.exe, sandbox/IP checks, and self-deletion.
Its theft capabilities include keystroke logging, screenshot capture, clipboard theft, credential harvesting, and collection of browser data such as saved passwords, cookies, and autofill information. Reporting also states it targets email client data, including Outlook credentials and artifacts, and in one campaign monitored clipboard contents to replace copied cryptocurrency wallet addresses with attacker-controlled values. Exfiltration methods described in the content include HTTP POST to PHP endpoints, SMTP, and Telegram-based command-and-control/exfiltration. High-confidence infrastructure and indicators mentioned in the content include SHA256 d6255b39e2be431e6226c8414b75721a16c114960f8a87acc06ea9fa7563006f for an analyzed loader sample; SHA256 0cae791ae86fd4960e6f9d62aac7941b1eee669e8ae373b28b32fba45e4bf46e and ca9e6eb1c8f2be20eaf9c220cf8482c264edd9c42389fc391eeed41dfe8de59b for extracted executables; SHA256 68e9d013f0867dfe02f531a17b0a08a8642b1fe49a8d9c8ec5f5bfdf8ec42199 for a dumped payload; C2 URLs hxxp://varders.kozow.com:8081, hxxp://aborters.duckdns.org:8081, hxxp://anotherarmy.dns.army:8081, and http://51.38.247.67:8081/; IPs 89.208.29.130, 69.55.5.249, 141.226.236.91, and 3.23.155.57; and SMTP-related indicators mail.wiramas.com.my, rosli@wiramas.com.my, and williamslucy570@gmail.com. Observed targeting in reporting spans organizations in multiple countries including the UK, Spain, France, the Netherlands, Switzerland, Belgium, Mauritius, India, Brazil, Botswana, Ghana, and Benin, with affected sectors including logistics, engineering, manufacturing, energy, government, finance, tourism, healthcare, and consumer goods. The content does not provide a high-confidence attribution to a specific threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Associated Analytic Story VIP Keylogger ... References ... https://malpedia.caad.fkie.fraunhofer.de/details/win.vipkeylogger
34 distinct techniques documented for this family, organized by ATT&CK tactic.
The console output of concatenated data from various variables, after being deobfuscated, results in another PowerShell command... The decoded string, in turn, contains another PowerShell script.
The preceding few lines execute the current batch file with a minimized window and also copy itself to the user profile directory with the name aoc.bat.
The initial infection begins with one of three script file types: a Visual Basic Script (.vbs), a JavaScript file (.js), or a batch script (.bat).
The file opened in Notepad appears to be obfuscated. The data present within %% can be replaced to create a meaningful batch command... All the next lines contain similar obfuscation... The PowerShell command contains a string that contains a replacement of “ghobbwnmfz”.
One of the most creative tricks in VIP Keylogger’s playbook is steganography, where malicious code is hidden inside what appear to be ordinary image files.
Inside, the archives contained executables disguised as legitimate documents, which deployed VIP Keylogger upon execution.
Only after those images are decoded does the actual keylogger emerge and get injected into a legitimate Windows process called aspnet_compiler.exe.
It also checks the victim’s IP address against known sandbox environments to avoid analysis, and deletes itself from disk after execution to cover its tracks.
The formed string after replacement contains a base64 encoded string... The decoded string, in turn, contains another PowerShell script... Then, it was decrypted using AES and uncompressed using gzip.
It also checks the victim’s IP address against known sandbox environments to avoid analysis, and deletes itself from disk after execution to cover its tracks.
Screenshots and clipboard data can be exfiltrated along with keystrokes.
Along with browser data like saved passwords, cookies, and auto-fill information, it can also target email clients.
Screenshots and clipboard data can be exfiltrated along with keystrokes.
Screenshots and clipboard data can be exfiltrated along with keystrokes.
The malware contacts multiple command-and-control servers to send stolen data, including through a Telegram bot.
The first part, after performing the previously mentioned operations, results in an executable file, The second part, after performing the previously mentioned operations, also results in an executable file. | The preceding few lines execute the current batch file with a minimized window and also copy itself to the user profile directory with the name aoc.bat.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information-stealing malware delivered via phishing using multi-stage script loaders (.vbs, .js, .bat), obfuscated PowerShell stagers, and steganography in PNG files. It injects into aspnet_compiler.exe, captures keystrokes, takes screenshots, steals browser passwords and cookies, harvests Outlook credentials from the registry, monitors and hijacks clipboard cryptocurrency wallet addresses, exfiltrates data to multiple C2 servers including via a Telegram bot, performs sandbox/IP checks, and deletes itself from disk after execution.
The content only references VIP Keylogger as an associated analytic story/reference. No direct behavioral description is provided in the content beyond its name implying keylogging functionality.
Referenced as part of a campaign associated with malware loaders and stagers that use PowerShell environment-variable execution to stage and run payloads.
The content links this detection to the VIP Keylogger analytic story, indicating relevance to activity associated with this malware. No direct behavioral description of the malware itself is provided in the content beyond its name and keylogger classification.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.