216.73.216.6

Masslogger Fileless Variant – Spreads via .VBE, Hides in Registry

· Published 18/06/2025 17:19 · Modified 23/06/2025 19:54

Export JSON

Essential information

Published
18/06/2025 17:19
Modified
23/06/2025 19:54
Tags
2025-06-18 credential-stealer data exfiltration fileless malware masslogger obfuscation persistence process-hollowing vbscript windows registry
Related entities
1 observables, 33 techniques (mitre)

Description

A sophisticated variant of the credential stealer malware has been identified spreading through .VBE files. This multi-stage heavily relies on to store and execute its malicious payload. The infection begins with a .VBE file, likely distributed via spam email or drive-by downloads. The malware sets up registry keys for storing commands, stager configurations, and the final payload. It establishes through a scheduled task and uses techniques to simulate user input. The malware employs multiple stagers to decode and load the final payload, which is injected into the AddInProcess32.exe process. The payload targets multiple web browsers and email clients to steal credentials and sensitive information, with capabilities including keylogging, screen capture, and via FTP, SMTP, or Telegram.

External references