PULSE NAME
MAAS VIP_Keylogger Campaign
WHITE AlienVault 2026-03-16 Modified: 2026-03-16
17
IOCs
MEDIUM VOLUME
A sophisticated keylogger campaign has been discovered, utilizing spear-phishing emails with attachments containing hidden malware. The campaign targets multiple countries, employing various packaging styles and execution methods. The malware, known as VIP_Keylogger, is delivered using steganography and process hollowing techniques. It focuses on stealing sensitive information from browsers, email clients, and other applications. The keylogger captures browser data, decrypts passwords, and exfiltrates information through multiple channels, including email. While some features appear disabled, the malware demonstrates advanced capabilities in data theft and evasion techniques.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
VIP_Keylogger
Indicators of Compromise (3 / 17 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 hostname
TYPEINDICATORDESCRIPTIONCREATED
hostname aborters.duckdns.org 2026-03-16
hostname anotherarmy.dns.army 2026-03-16
hostname varders.kozow.com 2026-03-16