VIP Recovery is a multi-stage Windows malware campaign observed in January 2026 and also referred to by some sources as "VIP Keylogger," though the exfiltration emails were labeled "VIP Recovery." The documented infection chain began with a phishing email, including one example sent from "Ms. Maggie Wu" with the subject "Request for Quotation (RFQ) -RFQ/2026/10/26," carrying a password-protected 7-zip archive. The archive contained a VBS script, "Documented_Invoice_305.vbs," which downloaded additional payloads from legitimate cloud storage services including firebasestorage.googleapis[.]com and 1zil1.s3.cubbit[.]eu. Those payloads included a JPEG image and a text file containing embedded base64-encoded executables that were extracted and executed. The recovered payloads were PE32 and PE32+ Mono/.NET assemblies targeting Windows systems. Post-infection activity included communications with checkip.dyndns[.]org, reallyfreegeoip[.]org, and api.telegram[.]org, indicating use of external IP/geolocation services and possible Telegram-based command-and-control or notification. Data theft/exfiltration was observed via FTP in one reporting context and via unencrypted SMTP traffic in another, specifically to eraqron[.]com on port 587, with stolen data sent from rejump@eraqron[.]shop to jump@eraqron[.]shop. Associated infrastructure mentioned in reporting includes morecft[.]shop, eraqron[.]com, and eraqron[.]shop. Reported tradecraft includes password-protected archives, VBS-based staging, use of cloud-hosted payload delivery, and multi-stage execution designed to evade detection. Mentioned artifacts include password-protected ZIP files and associated files sized 1,538 bytes, 2,128,478 bytes, 6,324 bytes, and 1,898,188 bytes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
VIP Recovery is a keylogger and infostealer malware delivered via email attachments. It exfiltrates stolen data via SMTP to attacker-controlled email addresses. The infection chain involves a malicious VBS file that downloads and executes additional payloads, including .NET-based executables, and uses various cloud storage services for payload delivery.
Ransomware infection referenced alongside FTP-based data exfiltration activity; indicates a likely double-extortion style operation involving theft of data (packaged in password-protected ZIP archives) in addition to any encryption activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.