Skip to content
ThreatCluster

VIP Keylogger Campaign Targets Businesses with Phishing Emails

First seen 28 May 2026, 16:06 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 29, 2026 at 15:45 UTC
  • VIP Keylogger is spread via phishing emails disguised as business documents.
  • The campaign employs advanced techniques like steganography and in-memory execution.
  • Organizations are at high risk due to the deceptive nature of the phishing emails.

Hackers are deploying VIP Keylogger through phishing emails disguised as routine business documents, targeting organizations to steal sensitive data. These campaigns utilize advanced techniques such as multi-layered loaders and steganography to execute the malware in-memory. The phishing emails often mimic legitimate communications, including bank payment notifications and procurement orders, making them particularly deceptive. The ongoing campaign has been active for several months, indicating a sustained threat to businesses. No specific numbers of affected organizations or systems were provided, but the scope of impact is significant given the nature of the malware. Security professionals are urged to remain vigilant against these types of phishing attacks. Current status indicates that the campaign shows no signs of abating.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 114d ago How this analysis works

Timeline

Recent
Ongoing VIP Keylogger campaign identified
Hackers have been actively deploying VIP Keylogger through phishing emails for several months, targeting businesses.
Gbhackers
Recent
Phishing emails mimic legitimate business communications
Emails crafted to look like bank payment notifications and procurement orders are being used to distribute the malware.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track VIP Keylogger in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed