Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

MassLogger

61
Global rank
49 infographic chevron month
Month rank
53 infographic chevron week
Week rank

MassLogger is a credential stealer and keylogger first identified in April 2020. It has been actively used in cyber campaigns to exfiltrate sensitive information from compromised systems. It is designed for easy use by less tech-savvy actors and is prominent for the capability of spreading via USB drives. It targets both individuals and organizations in various industries, mostly in Europe and the USA.

Keylogger
Type
Unknown
Origin
4 January, 2020
First seen
15 September, 2026
Last seen

How to analyze MassLogger with ANY.RUN

Type
Unknown
Origin
4 January, 2020
First seen
15 September, 2026
Last seen

IOCs

IP addresses
107.174.192.179
150.171.28.11
118.194.235.187
208.95.112.1
188.114.96.3
149.154.167.99
104.18.23.222
2.16.204.161
142.251.155.119
142.251.20.132
139.99.85.213
74.178.240.51
154.91.34.165
104.26.12.64
142.250.154.97
172.217.117.4
154.23.184.57
98.177.107.142
23.59.18.102
142.251.14.95
Hashes
74441313bb1fb62500484443c4937e90d4e335351a4fcd12a9ac48448500e33e
2ed27c1421e6928dbe13dbfdb5c59e1045b30341fe7ebe05700006bc5ac572c0
4094d158e3b0581ba433a46d0dce62f99d8c0fd1b50bb4d0517ddc0a4a1fde24
99653a38c445ae1d4c373ee672339fd47fd098e0d0ada5f0be70e3b2bf711d38
c158322bd963d2a68ffc878d72213a7394d8c16de72279771ffc924365eec0df
59345c006cd9bde5ef532aae1f119758d45030993181c272bb0dd6fc0c5d01e5
2ae1142b08d296c25000e451237ea919f981da28f6a723d39540f43f18bac762
5639c845d56dedecd2cfdb082b734593b5d618a87f1bd8ec612a8b3f4245566a
32ae9531405ef3c59448fe6dbd3be435e726eb17f3ca0d16530a4c6317dea286
7c68f28c6995f47dd77596bab28c6b4388ff93840c3becfd37733ddb640cd0cd
40cf1af5650b699a947899d2b43a00dcb64cdeaf080651c82a7930910c1c03f4
ec249b0dab6fda20cc24f0f25a504c55a05b23fb6cbb4938aa7a41df0c8744b6
0162159b64eb092f94964faf937f263fb9947b25d40e0d82bd3224d136a140de
77eed9211cd8464482f0da3fac4c0f003c2b8a6d76f15445927e66400f102d60
6558013f984e594bb57534910ce0b17bfa15da3cc9bb4b6e0b5c6e4ddf9eb14e
a7109b8374dffa7a0cd69558990f7e96fea9ef61736d89043dad5a6694cdfa4a
758a0b404b3daadbd0d4e88a0bedf5c21d5507392f7b54d4906ffea49d58ab32
558bbe6193a202dcb00cc441421f5d838764e495b8e4d2e10877db7f661b8cd5
db3ac1fd3d65df45d805adb8dfe0c5209db07ef93406db17dfb783dd8048720a
19acfa0adce363a9c9a3be73f5ec0fac0dcf3c630ce18125fd265040ad6ffb6c
Domains
tpc.googlesyndication.com
api.edgeoffer.microsoft.com
fe3cr.delivery.mp.microsoft.com
settings-win.data.microsoft.com
static.admaster.cc
msedge.b.tlu.dl.delivery.mp.microsoft.com
identitytoolkit.googleapis.com
lh3.googleusercontent.com
must-directed.gl.at.ply.gg
api.telegram.org
edge.microsoft.com
googleads.g.doubleclick.net
activation-v2.sls.microsoft.com
bucket-cf-weur-a.uploadnow.io
nexusrules.officeapps.live.com
www.bing.com
api.pcloud.com
client.wns.windows.com
slscr.update.microsoft.com
edge-consumer-static.azureedge.net
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:wre-eutrtw_lzyylfryn5gipqsah5d90nzfi4jwh-im&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://uploadnow.io/f/0bcds7g
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://uploadnow.io/en/share?utm_source=0bcds7g
https://cdn.uploadnow.io/_next/static/css/df97d9751ec3abda.css
https://cdn.uploadnow.io/_next/static/css/cda03e3a1ab65c17.css
https://cdn.uploadnow.io/_next/static/css/ae110469aab9e883.css
https://cdn.uploadnow.io/_next/static/css/5ded0d5ca9ecc5c1.css
https://cdn.uploadnow.io/_next/static/chunks/webpack-541c27ed8494cc3b.js
https://cdn.uploadnow.io/_next/static/chunks/framework-b6335179e7eea00c.js
https://cdn.uploadnow.io/_next/static/chunks/main-86f0684c1b20f38d.js
https://cdn.uploadnow.io/_next/static/chunks/pages/_app-a7a0c0b843b84887.js
https://cdn.uploadnow.io/_next/static/chunks/62867-950590631f5ceb03.js
https://cdn.uploadnow.io/_next/static/chunks/38993-a4121c3c0d1b9d33.js
https://cdn.uploadnow.io/_next/static/chunks/41480-7aa8c357827879bd.js
https://cdn.uploadnow.io/_next/static/chunks/3816-6a0007c41b67cb89.js
Last Seen at
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 1129
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 1423
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 3017
comments 0

What is MassLogger malware?

MassLogger is a sophisticated .NET-based malware classified as a credential stealer and keylogger observed from April 2020. It has since evolved with regular updates from its creator, known as NYANxCAT, who is also linked to other malware like LimeRAT and AsyncRAT.

Its high configurability, evasion techniques, and broad targeting capabilities, as well as the price of approximately $100, made it a popular item on dark web forums. It affects both individual users and organizations, with campaigns targeting industries like manufacturing, banking, and logistics across regions such as Europe (Turkey, Latvia, Italy, etc.), the U.S., and beyond.

MassLogger typically infiltrates networks through social engineering tactics, most often via phishing emails. They may target business users and masquerade as legitimate correspondence, such as procurement requests, shipping notices (e.g., referencing companies like Maersk), or other professional communications.

It can also spread via USB drives by injecting itself into files, infecting new systems when those files are opened.

In some campaigns, MassLogger has been distributed via compiled HTML files (.chm), which, when opened, execute embedded JavaScript to initiate the infection chain.

The infection chain is often multi-staged, involving scripting languages like PowerShell and .NET assemblies, making it harder to trace back to the initial vector.

TTPs of MassLogger attacks MassLogger tactics and techniques via MITRE ATT&CK Matrix

MassLogger is highly efficient at collecting and exfiltrating data. It extracts credentials from a wide range of applications, including web browsers (Chrome, Firefox, Edge), email clients (Outlook, Thunderbird, Foxmail), messaging apps (Discord, Telegram, Pidgin), VPN services (NordVPN), and FTP clients (FileZilla). It can also extract cryptocurrency wallet data.

Besides, it engages keylogging, clipboard monitoring, screen capturing, gathering system info via WMI queries.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

MassLogger Stealer’s prominent features

  • Abuses USB drives to infiltrate systems via infected files
  • To faster achieve its goals and avoid detection, can work without persistence mechanisms
  • Extracts data from a wide range of apps, including browsers, messengers, VPNs, network clients etc.
  • Available as a Malware-as-a-Service (MaaS) tool for $100 which amplifies its reach
  • The focus on fresh session cookies and 2FA bypass (via anti-detect browsers) heightens its threat to modern authentication systems.

MassLogger execution process and technical details

All the variety of MassLogger’s vicious ways is illustrated by fresh malware samples and analyses in ANY.RUN’s Interactive Sandbox. Let’s view one of the recent analysis sessions.

See MassLogger’s sample in action

The intrusion often begins with a phishing email containing a malicious attachment — typically a RAR-compressed archive with an unusual filename extension, such as .chm or .pif — used to bypass email filters. In the past, Microsoft Office files were also commonly used.

The main payload is a variant of the MassLogger Trojan, designed to retrieve and exfiltrate user credentials from various applications, including web browsers, email clients, and VPNs. After the payload is decrypted, MassLogger parses its configuration to target specific applications.

MassLogger’s process in ANY.RUN MassLogger acting in the system, malicious process detected by the sandbox

In some cases, it may be configured as a keylogger, though this functionality is often disabled depending on the campaign. The malware collects credentials from targeted applications and stores them in a log file — typically named Log.txt — in a temporary directory within %APPDATA%. Sometimes, it sends stolen information directly from memory without writing it to disk.

The stolen credentials are exfiltrated using methods such as FTP (File Transfer Protocol) or SMTP (Simple Mail Transfer Protocol). In certain scenarios, the data is sent via email to a compromised mailbox, encoded in Base64. MassLogger generally does not persist on the system after execution, meaning it does not install components that would automatically restart upon a system reboot. It also does not request updates from the threat actor over time, making it a relatively straightforward yet effective credential-stealing tool.

MassLogger employs several advanced evasion techniques:

  • Obfuscation: Its .NET code is heavily obfuscated, using techniques like polymorphic string encryption, hash-based import resolution, and indirect method calls to hide its control flow from static analysis. Tools like de4dot can partially deobfuscate it, but the latest versions (e.g., v3) use complex interpreters and uninitialized field calls.
  • Anti-Analysis: It checks for virtualization or sandbox environments and terminates if detected. It also looks for security software like Avast or AVG, halting execution if found.
  • Dynamic Execution: By replacing Microsoft Intermediate Language (MSIL) at runtime, it thwarts static analysis tools like dnSpy, requiring dynamic analysis to reveal its true behavior.
  • Fileless Techniques: Operating in memory rather than writing to disk minimizes detectable artifacts.
  • Encrypted Configuration: Its configuration (e.g., C2 server details) is encrypted within the payload, decrypted only at runtime using standard .NET cryptographic functions.
  • *Legitimate Traffic Mimicry: Exfiltration over SMTP or FTP blends with normal network traffic, avoiding suspicion from basic monitoring tools.

These tactics make MassLogger a "noisy" yet stealthy stealer, balancing aggressive data theft with efforts to remain undetected.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

What are the examples of successful MassLogger campaigns?

  • Compiled HTML (CHM) Campaign (Early 2021): Cisco Talos documented a significant MassLogger campaign notable for its use of Microsoft Compiled HTML Help (.CHM) files as the initial infection vector. This marked a shift from earlier delivery methods, showcasing the malware’s adaptability. Attackers sent phishing emails with subjects like “Domestic customer inquiry” or “MOU Information,” targeting users in Europe. The emails contained RAR attachments that, when extracted, revealed .CHM files embedding JavaScript to launch the infection chain.
  • Procurement-Themed Phishing Wave (August 2021): Cyberint Research identified a series of campaigns in August 2021 targeting manufacturing and banking sectors, particularly in Europe, with phishing emails disguised as procurement requests. Emails included attachments like RAR files or Office documents with macros, delivering MassLogger to steal credentials from browsers, email clients, and VPN services. The malware exfiltrated data via SMTP to compromised mailboxes, storing stolen information in a "Log.txt" file in the %APPDATA% directory.
  • XLS-Based Industrial Targeting (March 2025): A recent campaign, noted in posts on X around March 30, 2025, involved phishing emails with fake procurement themes and malicious Excel (.XLS) files distributing MassLogger. It focused on stealing sensitive data from business applications, with exfiltration via SMTP or HTTP to attacker-controlled servers. The global scope and industrial focus suggested a continuation of MassLogger’s evolution into a tool for both broad and targeted attacks, potentially linked to initial access brokers supplying larger cybercrime groups.

These campaigns highlight MassLogger’s key strengths: its configurability, low entry cost, and evasion tactics like obfuscation, fileless execution, and anti-analysis checks. Unlike headline-grabbing ransomware attacks, MassLogger’s impact is often quieter but insidious, focusing on credential theft that can lead to downstream breaches.

Gathering threat intelligence on MassLogger

Threat intelligence is of much help in proactive defending against MassLogger. Use ANY.RUN’s Threat Intelligence Lookup to gather IOCs, study attackers’ TTPs, preempt incidents by blocking known C2 infrastructure.

Start by searching MassLogger in TI Lookup by the name and explore malicious samples that the cybersecurity community using ANY.RUN’s tools have encountered.

threatName:"masslogger"

MassLogger search results in TI Lookup MassLogger samples submitted in the Sandbox and filtered via TI Lookup

Explore each session to collect new IOCs and use them for further research. Enrich your monitoring and detection systems with the harvested indicators.

MassLogger’s IOCs in Sandbox Click the IOC button in the top right block of the analysis view interface in the Sandbox

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

MassLogger’s combination of accessibility, evasion tactics, and broad data theft capabilities makes it a formidable threat. Its reliance on phishing and fileless execution demands robust email security and endpoint protection, while its stealth requires advanced threat intelligence to stay ahead of evolving campaigns.

By combining behavioral detection, network monitoring, and proactive intelligence-driven countermeasures, organizations can effectively mitigate its risks.

Start building your defenses against MassLogger with 50 requests in TI Lookup

HAVE A LOOK AT

DonutLoader screenshot
DonutLoader
donutloader donut
DonutLoader is a versatile, open-source-based in-memory loader that turns .NET assemblies, executables, DLLs, and scripts into position-independent shellcode for execution entirely in RAM. Originally derived from the popular Donut tool, it enables threat actors to bypass traditional antivirus and EDR solutions by avoiding disk writes and injecting payloads directly into legitimate Windows processes.
Read More
EvilTokens screenshot
EvilTokens
eviltokens
EvilTokens is a phishing-as-a-service (PhaaS) toolkit that emerged in mid-February 2026. It automates device code phishing attacks against Microsoft 365 and Entra ID environments. Unlike traditional credential-harvesting phishing, EvilTokens tricks users into completing legitimate authentication on Microsoft's own login pages, resulting in the issuance of valid OAuth access and refresh tokens directly to the attacker, effectively bypassing MFA without stealing passwords.
Read More
Remote Access Trojan screenshot
Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.
Read More
DarkComet screenshot
DarkComet
darkcomet rat darkcomet rat
DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.
Read More
Chaos Ransomware screenshot
Chaos ransomware is a malware family known for its destructive capabilities and diverse variants. It first appeared in 2021 as a ransomware builder and later acted as a wiper. Unlike most ransomware strains that encrypt data to extort payment, early Chaos variants permanently corrupted files, while later versions adopted more conventional encryption techniques.
Read More
 screenshot
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More