216.73.216.6

VIPKeyLogger Infostealer in the Wild

· Published 16/12/2024 12:46 · Modified 16/12/2024 14:33

Export JSON

Essential information

Published
16/12/2024 12:46
Modified
16/12/2024 14:33
Tags
2024-12-16 CVE-2017-11882 infostealer keylogger snake keylogger vipkeylogger
Related entities
14 techniques (mitre), 3 malware

Description

A new called has been observed with increased activity. It shares similarities with and is distributed through phishing campaigns. The malware is delivered as an archive or Microsoft 365 file attachment, which downloads and executes a .NET compiled file. utilizes steganography to hide obfuscated code within a bitmap image. It exfiltrates various data types including PC names, country names, clipboard data, screenshots, cookies, and browser history. The stolen information is sent via Telegram to Dynamic DuckDNS C2 servers. The attack chain involves multiple stages, from initial email lure to payload execution and data exfiltration.

External references