MASS Logger
- First seen
- 2020-04-01 00:00:00
- Malware type
- credential-stealer, keylogger, loader
- Family
- Malware family
- Last IoC activity
- 2026-07-21 22:47:07
- Profile updated
- 2026-07-07 15:11:18
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:de country_code:tr
Context
MassLogger is a .NET credential stealer. It starts with a launcher that uses simple anti-debugging techniques which can be easily bypassed when identified. This first stage loader eventually XOR-decrypts the second stage assembly which then decrypts, loads and executes the final MassLogger payload.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Masslogger (report)
- Cisco Talos — A Year Of Fajan Evolution And Bloomberg (report)
- seqrite.com — Masslogger Fileless Vbe Registry Malware (report)
- decoded.avast.io — Masslogger V3 A Net Stealer With Serious Obfuscation (report)
- maxkersten.nl — Rezer0V4 Loader (report)
- fr3d.hk — Masslogger Frankenstein S Creation (report)
- twitter.com — 1255893734241304576 (report)
- Cisco Talos — Masslogger Cred Exfil (report)
- gdatasoftware.com — 36129 Harmful Logging Diving Into Masslogger (report)
- seqrite.com — Masslogger An Emerging Spyware And Keylogger (report)
- Mandiant — Bypassing Masslogger Anti Analysis Man In The Middle Approach (report)
- netresec.com (report)
- medium.com — Decrypt Masslogger 2 4 0 0 Configuration Eff3Ee0720A7 (report)