VIPKeylogger is a Windows infostealer and keylogger that is widely assessed as a variant or rebrand of SnakeKeylogger, also known as 404 Keylogger. It is used in credential-theft operations and has been observed in broad malspam and phishing campaigns, including business-themed lures such as orders, requests, quotes, invoices, offers, payments, and shipping notices, as well as brand-themed delivery lures and tax-authority impersonation. Activity has been repeatedly observed against organizations and users in Italy and in wider international campaigns.
The malware is designed to harvest sensitive information from infected systems. Reported capabilities include theft of credentials and other victim data, keylogging, and exfiltration of collected information to attacker-controlled infrastructure. Multiple analyses associate VIPKeylogger with dual or alternate exfiltration channels, especially Telegram Bot API and SMTP, and some campaigns place it within broader credential-theft ecosystems that also use FTP or other channels for related malware families. VIPKeylogger has also been observed sending victim notifications through Telegram.
Observed delivery chains show substantial use of script-based loaders and multi-stage execution. Campaigns have used phishing emails carrying archives or script attachments, including VBS and JavaScript droppers, followed by PowerShell stages, reflective .NET loading, AutoIT-based loaders, shellcode execution, and process injection or hollowing into legitimate Windows binaries. Some samples established persistence through Run-key entries, startup scripts, or scheduled tasks, and some employed anti-analysis or obfuscation techniques to hinder detection.
VIPKeylogger appears in commodity cybercrime operations rather than exclusively in state-linked activity. It is commonly clustered with other credential-stealing malware such as AgentTesla, FormBook, Remcos, PureLogs, and PhantomStealer in malspam reporting, and has been advertised alongside SnakeKeylogger by the same operator ecosystem. Its role in stealing credentials makes it relevant to financially motivated intrusion activity and to downstream initial-access abuse.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
This first script is pretty simple: it decodes a Base64 payload, dumps it on disk with a random name and invokes a PowerShell interpreter to decompress it... Another PowerShell will be invoked to dump three new files on disk...
The archive contains a VBS script... This first script is pretty simple: it decodes a Base64 payload, dumps it on disk with a random name and invokes a PowerShell interpreter to decompress it.
Yes, AutoIT is able to invoke any API call!... OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread, CloseHandle
This script will decode the shellcode (XOR key 0xEC), launch a charmap.exe, inject and launch the payload via the following API calls: OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread
launch a charmap.exe, inject and launch the payload via the following API calls: OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread
These files are Base64 encoded and XOR with the keys 0x02 and 0x3D... This script will decode the shellcode (XOR key 0xEC)...
This script will decode the shellcode (XOR key 0xEC), launch a charmap.exe, inject and launch the payload via the following API calls: OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread
Other kinds of highly sensitive data that infostealers often collect are screenshots, keylogs, clipboard, cryptocurrency wallets and autofill data, the latter occasionally containing credit card info.
This type of malware steals all kinds of data from the system it infects, including credentials (passwords and cookies) for VPNs, RDP, business services, banking and social media, stored by a variety of apps (including popular browsers like Chrome and Firefox).
Infostealers are a type of trojan used extensively by malware authors to harvest sensitive data types like login details, financial information, system data and personal identifiable information.
Other kinds of highly sensitive data that infostealers often collect are screenshots, keylogs, clipboard, cryptocurrency wallets and autofill data, the latter occasionally containing credit card info.
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A keylogger payload delivered by shellcode after an AutoIT-based infection chain involving process injection into charmap.exe.
A password-stealing/keylogging malware family observed in Italian malspam campaigns during the reporting week.
VIPKeylogger is listed among the password-stealing malware families distributed in the observed malspam campaigns, including order- and offer-themed emails.
Keylogger malware distributed via an Italian malspam campaign themed around requests.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.