logo

MaaS VIP Keylogger Campaign Uses Steganography and In-Memory Execution to Steal Credentials at Scale

ID: 779c72e0-67d8-5812-bade-8366d8960a22

STIX ID: report--779c72e0-67d8-5812-bade-8366d8960a22

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A widespread spear‑phishing campaign distributes VIP Keylogger — an in‑memory, modular credential‑stealing malware that harvests credentials, cookies, credit‑card data and tokens from numerous browsers, email clients and apps and exfiltrates via SMTP, FTP, Telegram, HTTP POST or Discord; it evades detection using steganography, process hollowing and AMSI/ETW bypass and appears offered as configurable Malware‑as‑a‑Service, enabling scaled abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.