logo

MaaS VIP Keylogger Campaign Uses Steganography to Steal Credentials at Scale

ID: 6697e527-7a9a-5200-ba89-e9faeeb12342

STIX ID: report--6697e527-7a9a-5200-ba89-e9faeeb12342

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A large-scale spear-phishing campaign distributes a VIP Keylogger (MaaS) via fraudulent purchase-order lures and RAR-attached executables; the malware employs steganography and in-memory execution (process hollowing, AMSI/ETW bypass) to steal credentials, cookies, and payment data from 40+ Chromium-based browsers and various email/communication clients, exfiltrating data via SMTP, FTP, Telegram, Discord, and web POSTs, with several sample hashes and sender metadata provided as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.