VIP Keylogger is a Windows-focused .NET information stealer and keylogger distributed in commodity phishing campaigns, often using impersonated business correspondence such as purchase orders, quotations, shipment notices, and sales contracts. Delivery chains have included malicious archives containing executables disguised as documents, and heavily obfuscated VBScript, JScript, or batch-script loaders that reconstruct PowerShell stagers. Some campaigns use steganographic payload components embedded in PNG images.
VIP Keylogger captures keystrokes, screenshots, clipboard contents, browser-saved passwords, cookies, autofill data, and Microsoft Outlook-related credentials or data. Some variants also replace cryptocurrency wallet addresses copied to the clipboard. Collected information is exfiltrated through web requests, SMTP, and in some observed campaigns Telegram-based communications. Loaders and payloads employ layered encoding, encryption, compression, in-memory execution, obfuscation, hidden execution, telemetry and logging impairment, AMSI interference, anti-sandbox checks, and self-deletion. Observed builds inject into legitimate Windows processes and may establish persistence through environment-variable or related configuration abuse.
Campaigns have targeted Windows users and organizations worldwide across logistics, engineering, manufacturing, energy, government, finance, tourism, healthcare, and consumer-goods sectors. No single threat actor attribution is established; the malware exhibits tradecraft overlap with other commodity .NET stealers, including Snake Keylogger.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Associated Analytic Story VIP Keylogger ... References ... https://malpedia.caad.fkie.fraunhofer.de/details/win.vipkeylogger
32 distinct techniques documented for this family, organized by ATT&CK tactic.
The concatenated data results in another PowerShell command, which ultimately decodes and runs further PowerShell scripts.
“Base64 encoded strings for data obfuscation”; the resource content is AES-decrypted and then GZIP-decompressed; the dumped .NET binary is also described as obfuscated.
One of the most creative tricks in VIP Keylogger’s playbook is steganography, where malicious code is hidden inside what appear to be ordinary image files.
“The function ... returns the contents of the file xxxx.exe from the manifest resources”; after AES decryption and GZIP decompression, the recovered data has an MZ executable header.
Only after those images are decoded does the actual keylogger emerge and get injected into a legitimate Windows process called aspnet_compiler.exe.
It also checks the victim’s IP address against known sandbox environments to avoid analysis, and deletes itself from disk after execution to cover its tracks.
Embedded content is extracted, concatenated, string-replaced, Base64 decoded, AES decrypted, and gzip decompressed to yield PowerShell scripts and two executable files.
The application executes with a hidden window. This is one of the capabilities we identified using Capa, being listed as 'hide graphical window'.
“Screenshots and clipboard data can be exfiltrated along with keystrokes.”
Along with browser data like saved passwords, cookies, and auto-fill information, it can also target email clients.
“Screenshots and clipboard data can be exfiltrated along with keystrokes.”
“Screenshots and clipboard data can be exfiltrated along with keystrokes.”
The first part, after performing the previously mentioned operations, results in an executable file, The second part, after performing the previously mentioned operations, also results in an executable file. | The preceding few lines execute the current batch file with a minimized window and also copy itself to the user profile directory with the name aoc.bat.
The strings indicate use of “a POST request to this web server,” with URLs using port 8081, and the article states collected screenshots, clipboard data, and keystrokes can be exfiltrated.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information-stealing malware delivered via phishing using multi-stage script loaders (.vbs, .js, .bat), obfuscated PowerShell stagers, and steganography in PNG files. It injects into aspnet_compiler.exe, captures keystrokes, takes screenshots, steals browser passwords and cookies, harvests Outlook credentials from the registry, monitors and hijacks clipboard cryptocurrency wallet addresses, exfiltrates data to multiple C2 servers including via a Telegram bot, performs sandbox/IP checks, and deletes itself from disk after execution.
The content only references VIP Keylogger as an associated analytic story/reference. No direct behavioral description is provided in the content beyond its name implying keylogging functionality.
Referenced as part of a campaign associated with malware loaders and stagers that use PowerShell environment-variable execution to stage and run payloads.
The content links this detection to the VIP Keylogger analytic story, indicating relevance to activity associated with this malware. No direct behavioral description of the malware itself is provided in the content beyond its name and keylogger classification.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.