Researchers reported that MassLogger, a .NET credential-stealing malware sold on criminal forums, has evolved from heavily obfuscated loader-based campaigns into a more stealthy fileless variant that stores staged payloads in the Windows Registry and executes them in memory. Seqrite said recent infections begin with a .VBE loader, progress through multiple .NET stagers, and ultimately inject the final payload into AddInProcess32.exe via process hollowing while maintaining persistence through a scheduled task. The malware can also check for installed security products and stop execution when multiple antivirus tools are present, adding another layer of defense evasion.
Analysis across multiple reports shows MassLogger consistently focuses on credential theft while using increasingly sophisticated anti-analysis techniques. Avast previously documented version 3 using encrypted configuration blobs, PBKDF2-derived keys, AES decryption, SHA-256 integrity checks, encrypted strings, and a large custom interpreter to conceal control flow, while newer samples avoid writing stolen data to disk. Related loader research found the ReZer0 .NET loader supports anti-VM and anti-sandbox checks, scheduled-task persistence, in-memory assembly loading, download-and-run behavior, and process hollowing. Seqrite added that the latest fileless variant can steal browser and email credentials, log keystrokes, capture clipboard data, collect host information, and exfiltrate data through FTP, SMTP, or Telegram, with one France-targeted branch attempting to fetch an additional payload from hxxps://144.91.92.251/MoDi.txt.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Seqrite Labs identified and analyzed a fileless MassLogger variant delivered through .VBE files that stores staged payloads in the Windows Registry and executes them in memory. The infection chain used VBScript and .NET stagers, established persistence with a scheduled task, and hollowed AddInProcess32.exe to run the final payload.
Avast published a technical analysis of MassLogger v3 describing its layered obfuscation, encrypted configuration handling, and interpreter-based execution. The analysis also noted newer variants refuse to run when Avast or AVG processes are detected and no longer write log data to disk.
Cisco Talos disclosed a credential-stealing campaign using a MassLogger variant delivered via phishing emails with .chm attachments, targeting Windows users in Turkey, Latvia, and Italy, with related 2020 waves also hitting several other European countries. Talos said the attack chain was almost entirely fileless after the initial attachment and that stolen credentials were exfiltrated over FTP to med-star.gr.
G DATA published a technical analysis of MassLogger describing it as a modular .NET credential stealer and spyware sold on hacker forums and promoted via YouTube videos. The analyzed sample used multiple packing stages and dnSpy detection, executed in memory with process injection, harvested credentials, could capture screenshots, and exfiltrated stolen data over SMTP while also supporting FTP.
MassLogger was first sold on hacking forums around April 2020 as a configurable credential theft and keylogging tool. The malware author advertised it as the “most powerful logger and recovery tool” and offered a lifetime license for $99 in Bitcoin.
Seqrite published an analysis of a 2020 MassLogger campaign distributed through malicious spam attachments, including archives and Office documents using VBA macros and CVE-2017-11882 to fetch the payload. The report detailed a multi-stage .NET infection chain with scheduled-task persistence, self-hollowing, data theft modules, and ZIP-based exfiltration of stolen information.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 263 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
seqrite.com
Open sourcedecoded.avast.io
Open sourceblog.talosintelligence.com
Open sourceseqrite.com
Open sourcegdatasoftware.com
Open sourcemaxkersten.nl
Open sourcefireeye.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.