VIPKeylogger is a Windows credential-stealing malware family commonly assessed as a variant or rebrand of SnakeKeylogger (also known as 404 Keylogger). It has been distributed extensively through business-themed phishing and malspam campaigns, including Italian-language operations using order, payment, invoice, quote, and request lures, as well as DHL- and banking-themed messages. Delivery chains have used malicious script attachments and archives, often progressing through VBScript, PowerShell, AutoIT, shellcode, or in-memory .NET loaders.
VIPKeylogger collects victim information and credentials and has been observed exfiltrating stolen data through SMTP and the Telegram Bot API, including simultaneous use of both channels. Observed variants employ obfuscation, hidden PowerShell execution, reflective in-memory loading, anti-analysis checks, and process injection or process hollowing into legitimate Windows processes. Persistence mechanisms observed include startup execution and scheduled tasks. Some variants perform external-IP and geolocation reconnaissance before exfiltration. Campaign reporting has primarily documented opportunistic credential-theft activity against Windows users and businesses, particularly targets in Italy; no specific threat actor attribution is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The Italian campaigns were grouped according to macro categories obtained from the subject of the email message used for malware distribution (malspam). Examples include FormBook-themed “Payments” and “Prices,” VIPKeylogger-themed “Orders” and “Payments,” Remcos-themed “Requests,” and AgentTesla-themed “Orders.”
This first script is pretty simple: it decodes a Base64 payload, dumps it on disk with a random name and invokes a PowerShell interpreter to decompress it... Another PowerShell will be invoked to dump three new files on disk...
The archive contains a VBS script... This first script is pretty simple: it decodes a Base64 payload, dumps it on disk with a random name and invokes a PowerShell interpreter to decompress it.
Yes, AutoIT is able to invoke any API call!... OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread, CloseHandle
This script will decode the shellcode (XOR key 0xEC), launch a charmap.exe, inject and launch the payload via the following API calls: OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread
launch a charmap.exe, inject and launch the payload via the following API calls: OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread
These files are Base64 encoded and XOR with the keys 0x02 and 0x3D... This script will decode the shellcode (XOR key 0xEC)...
This script will decode the shellcode (XOR key 0xEC), launch a charmap.exe, inject and launch the payload via the following API calls: OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread
Other kinds of highly sensitive data that infostealers often collect are screenshots, keylogs, clipboard, cryptocurrency wallets and autofill data, the latter occasionally containing credit card info.
This type of malware steals all kinds of data from the system it infects, including credentials (passwords and cookies) for VPNs, RDP, business services, banking and social media, stored by a variety of apps (including popular browsers like Chrome and Firefox).
Infostealers are a type of trojan used extensively by malware authors to harvest sensitive data types like login details, financial information, system data and personal identifiable information.
Other kinds of highly sensitive data that infostealers often collect are screenshots, keylogs, clipboard, cryptocurrency wallets and autofill data, the latter occasionally containing credit card info.
44 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A password-stealing keylogger family distributed in malspam campaigns targeting Italy during the reporting week.
A password-stealer family observed in a malspam campaign targeting Italy during the reporting week.
A keylogger payload delivered by shellcode after an AutoIT-based infection chain involving process injection into charmap.exe.
A password-stealing/keylogging malware family observed in Italian malspam campaigns during the reporting week.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.