Contact

VIPKeyLogger Infostealer in the Wild

NetmanageIT OpenCTI - opencti.netmanageit.com

VIPKeyLogger Infostealer in the Wild



SUMMARY :

A new infostealer called VIPKeyLogger has been observed with increased activity. It shares similarities with Snake Keylogger and is distributed through phishing campaigns. The malware is delivered as an archive or Microsoft 365 file attachment, which downloads and executes a .NET compiled file. VIPKeyLogger utilizes steganography to hide obfuscated code within a bitmap image. It exfiltrates various data types including PC names, country names, clipboard data, screenshots, cookies, and browser history. The stolen information is sent via Telegram to Dynamic DuckDNS C2 servers. The attack chain involves multiple stages, from initial email lure to payload execution and data exfiltration.

OPENCTI LABELS :

keylogger,infostealer,cve-2017-11882,vipkeylogger,snake keylogger


Open in NetmanageIT OpenCTI Public Instance with below link!


Use public read only username and password on login page.

NOTE : Use Public READ only user credentials on login page banner.


VIPKeyLogger Infostealer in the Wild