logo

Spear Phishing Campaign Delivers VIP Keylogger via EMAIL Attachment

ID: 31218dab-5cb9-598d-85a2-19aec755600e

STIX ID: report--31218dab-5cb9-598d-85a2-19aec755600e

Feed Name: Seqrite Blog

Threat Score
70/100

Date Published: 2025-07-29

Date Updated: 2026-04-30

Author: Vaibhav Billade

...
...

This report analyzes a spear‑phishing campaign that distributes a VIP Keylogger using an AutoIt-based injector: a malicious ZIP attachment runs an AutoIt script that decrypts payloads dropped to Temp, injects a .NET keylogger into RegSvcs.exe via process hollowing, establishes persistence with a startup VBScript, and exfiltrates stolen data to SMTP and a C2 server. The document includes technical details of the AutoIt decryption routine, memory injection steps, process tree visuals, IOCs (MD5s and an IP), MITRE ATT&CK mappings, and suggested detection labels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.