ThreatCluster

VIP Keylogger Campaign Targets Businesses with Phishing Emails

First seen 28 May 2026, 16:06 UTC GbhackersCybersecuritynews 91% similarity 65

Article Content

Browse articles
ThreatCluster

Hackers are deploying VIP Keylogger through phishing emails disguised as routine business documents, targeting organizations to steal sensitive data. These campaigns utilize advanced techniques such as multi-layered loaders and steganography to execute the malware in-memory. The phishing emails often mimic legitimate communications, including bank payment notifications and procurement orders, making them particularly deceptive. The ongoing campaign has been active for several months, indicating a sustained threat to businesses. No specific numbers of affected organizations or systems were provided, but the scope of impact is significant given the nature of the malware. Security professionals are urged to remain vigilant against these types of phishing attacks. Current status indicates that the campaign shows no signs of abating.

Key Points: • VIP Keylogger is spread via phishing emails disguised as business documents. • The campaign employs advanced techniques like steganography and in-memory execution. • Organizations are at high risk due to the deceptive nature of the phishing emails.

ThreatCluster AI

Timeline

Recent
Ongoing VIP Keylogger campaign identified
Hackers have been actively deploying VIP Keylogger through phishing emails for several months, targeting businesses.
Gbhackers
Recent
Phishing emails mimic legitimate business communications
Emails crafted to look like bank payment notifications and procurement orders are being used to distribute the malware.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story