MASS Logger

First seen
2020-04-01 00:00:00
Malware type
credential-stealer, keylogger, loader
Family
Malware family
Last IoC activity
2026-07-21 22:47:07
Profile updated
2026-07-07 15:11:18

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:de country_code:tr

Context

MassLogger is a .NET credential stealer. It starts with a launcher that uses simple anti-debugging techniques which can be easily bypassed when identified. This first stage loader eventually XOR-decrypts the second stage assembly which then decrypts, loads and executes the final MassLogger payload.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Masslogger (report)
  • Cisco Talos — A Year Of Fajan Evolution And Bloomberg (report)
  • seqrite.com — Masslogger Fileless Vbe Registry Malware (report)
  • decoded.avast.io — Masslogger V3 A Net Stealer With Serious Obfuscation (report)
  • maxkersten.nl — Rezer0V4 Loader (report)
  • fr3d.hk — Masslogger Frankenstein S Creation (report)
  • twitter.com — 1255893734241304576 (report)
  • Cisco Talos — Masslogger Cred Exfil (report)
  • gdatasoftware.com — 36129 Harmful Logging Diving Into Masslogger (report)
  • seqrite.com — Masslogger An Emerging Spyware And Keylogger (report)
  • Mandiant — Bypassing Masslogger Anti Analysis Man In The Middle Approach (report)
  • netresec.com (report)
  • medium.com — Decrypt Masslogger 2 4 0 0 Configuration Eff3Ee0720A7 (report)

External references