logo

Masslogger Fileless Variant – Spreads via .VBE, Hides in Registry

ID: 575daff1-ff8f-5477-b463-d7f9f119fafd

STIX ID: report--575daff1-ff8f-5477-b463-d7f9f119fafd

Feed Name: Seqrite Blog

Threat Score
72/100

Date Published: 2025-06-18

Date Updated: 2026-04-30

Author: Prashil Moon

...
...

This report analyzes a fileless Masslogger credential-stealer variant distributed via encoded VBScript (.VBE/.VBS) that writes obfuscated stagers and a segmented payload into HKCU registry keys, persists via a scheduled task, loads .NET assemblies in memory (stager-1 -> stager-2), uses process hollowing to inject the final Masslogger payload into AddInProcess32.exe, and exfiltrates harvested browser/email credentials and system data via FTP, SMTP or Telegram; the report includes MD5 hashes, a hardcoded URL, Seqrite detections and MITRE ATT&CK mappings to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.