#VIPKeylogger
-BEC scammer ABK captured and extradited
-Hacker steals 400k WP credentials from other threat actors
-Virtual card clone campaign targets Russia
-CISA warns of exposed WWS HMIs
-Okta warns of impersonation attacks
-Malware reports on PUMAKIT, SADBRIDGE, HeartCrypt, VIPKeyLogger, NodeLoader, Cloak
December 16, 2024 at 8:45 AM
Deep Analysis of Snake Keylogger’s New Variant : www.fortinet.com/blog/threat-...

In-depth Analysis of VIPKeyLogger : www.forcepoint.com/blog/x-labs/...
December 28, 2024 at 1:21 PM
Seqrite's Kirti Kshatriya analyses a malspam campaign with a steganographic stage leading to multiple stealers including Remcos, DcRAT, AgentTesla, VIPKeyLogger, etc. www.seqrite.com/blog/stegano...
March 17, 2025 at 9:27 AM
添付ファイルからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/09/07(月)
■件名
見積依頼>'IONIAN SEA'FTC-E4211926-01-S4661 MSD3
■添付ファイル
見積依頼書E4211926_01_S461[.]zip -> 見積依頼書E4211926_01_S461.js
www.virustotal.com/gui/file/d97...
tria.ge/260907-fvk56...
情報窃取マルウェア #VIPKeylogger ( #SnakeKeylogger )
■C2
webmail.ckvsb[.]com[.]my
September 8, 2026 at 2:30 AM
添付ファイルからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/08/12(水)
■件名
Re: 請求書
■添付ファイル
請求書.rar -> 請求書.js
virustotal.com/gui/file/dfc...
tria.ge/260812-j8tk9...
app.any.run/tasks/8016f9...
#DonutLoader #VIPKeylogger #SnakeKeylogger
■C2
mail.elpasohonroso[.]com

引用元:
x.com/tdatwja/stat...
August 14, 2026 at 3:30 PM
AutoIT-based phishing campaign targeting financial services with VIPKeylogger. Uses legitimate Windows binaries and process injection to steal banking credentials. Runs inside hidden charmap.exe to evade detection. #infosec #cybersecurity
AutoIT Payload Injector Delivers VIPKeylogger to Financial Services Firms
AutoIT-based phishing campaign targeting financial services with VIPKeylogger. Uses legitimate Windows binaries and process injection to steal banking credentials. Runs inside hidden charmap.exe to evade detection. #infosec #cybersecurity
captechgroup.com
July 29, 2026 at 8:06 PM
VIPKeylogger now runs inside charmap.exe - shellcode hiding in the Windows Character Map. https://intel.threadlinqs.com/threat/TL-2026-1740 #ThreatIntel #VIP #AutoIT3 #VIPKeylogger
July 28, 2026 at 8:09 AM
Notícia da SecurityOnline

"VIPKeyLogger: Um Novo Infostealer Focando Dados Sensíveis através de Campanhas de Phishing" #bolhasec
VIPKeyLogger: A New Infostealer Targeting Sensitive Data via Phishing Campaigns
Forcepoint researchers have uncovered an alarming rise in activity involving a new infostealer malware named VIPKeyLogger. Distributed through phishing campaigns, VIPKeyLogger demonstrates sophisticated techniques to harvest sensitive data from its... The post VIPKeyLogger: A New Infostealer Targeting Sensitive Data via Phishing Campaigns appeared first on Cybersecurity News.
securityonline.info
December 19, 2024 at 8:30 AM
VIPKeyLogger, un nouvel infostealer, se propage via des campagnes de phishing en pièces jointes (archives ou fichiers Microsoft 365) exécutant du code .NET. Utilisant la stéganographie, il vole des données (PC, captures d’écran, cookies, etc.) et les exfiltre via Telegram vers des serveurs DuckDNS.
LevelBlue - Open Threat Exchange
Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.
otx.alienvault.com
December 16, 2024 at 5:15 PM
Outdated Equation Editor Exploit: The Malware Gift That Keeps on Giving!

Patch your way to safety! CVE-2017-11882 is still causing havoc in Microsoft Office. Dive into this oldie but baddie vulnerability.
thenimblenerd.com?p=1052963
Outdated Equation Editor Exploit: The Malware Gift That Keeps on Giving!
CVE-2017-11882, the Microsoft Office vulnerability that refuses to retire, is still causing headaches. Attackers are exploiting it to spread malware, like a VIPKeyLogger, through seemingly innocuous files. Despite Microsoft's attempts to make life difficult for macro miscreants, this old vulnerability is the gift that keeps on giving—for cybercriminals.
thenimblenerd.com
August 13, 2025 at 8:36 AM
Forcepoint's Prashant Kumar looks into the VIPKeyLogger infostealer delivered via malspam in archives with malicious Office documents. www.forcepoint.com/blog/x-labs/...
December 17, 2024 at 10:59 AM
VIPKeyLogger: A New Infostealer Targeting Sensitive Data via Phishing Campaigns securityonline.info/vipkeylogger...
VIPKeyLogger: A New Infostealer Targeting Sensitive Data via Phishing Campaigns
Stay informed about the rise of VIPKeyLogger, a dangerous infostealer malware that poses significant risks to individuals and organizations.
securityonline.info
December 19, 2024 at 3:35 AM
2024-09-16 (Monday): Saw an #infostealer calling itself "VIP Recovery" which some might call #VIPKeyLogger. Further investigation indicates it's actually #SnakeKeyLogger. Indicators and more info available at bit.ly/3XLR715 #Unit42ThreatIntel
Unit42-timely-threat-intel/2024-09-16-IOCs-for-Snake-KeyLogger.txt at main · PaloAltoNetworks/Unit42-timely-threat-intel
A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence. - PaloAltoNetworks/Unit42-timely-threat-intel
bit.ly
September 17, 2024 at 9:33 PM
Ontinet :
Nueva campaña de emails maliciosos con falsas facturas propaga VIPKeylogger infostealer

https://ontinet.com/blog/protegerse-6/nueva-campana-de-emails-maliciosos-con-falsas-facturas-propaga-vipkeylogger-infostealer-4626
June 17, 2025 at 8:45 PM