Viper A.I CyberSecurity Scoring
Viper
Company Information
Website:https://www.nilfisk.com/global/about-nilfisk/brands/viper/
Employees number:140
Number of followers:1,543
NAICS:333
Industry Type:Machinery Manufacturing
Homepage:nilfisk.com
Viper Risk Score (AI oriented)
Between 700 and 749
ViperMachinery Manufacturing
Updated:
10/03/2026
10/03/2026
735/1000
Moderate
Ba
Viper Global Score (TPRM)
xxxx
ViperMachinery Manufacturing
Score locked

ViperModerate
Current Score
735Ba (MODERATE)
01000
1 incidents
-11 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
737
MAY 2026
736
APRIL 2026
736
MARCH 2026
746
Cyber Attack
10 Mar 2026 • Viper
VIP Keylogger: VIP Keylogger Malware Campaign Hides In Images To Steal Credentials At Scale
New VIP Keylogger Malware Campaign Targets Credentials via Phishing and Stealthy Execution
735
CRITICAL-11
VIP1773145966
New VIP Keylogger Malware Campaign Targets Credentials via Phishing and Stealthy Execution
A recently uncovered malware campaign is deploying VIP Keylogger to steal credentials through sophisticated phishing tactics, hidden payloads, and in-memory execution techniques. The attacks begin with social engineering, luring victims into opening a seemingly legitimate "purchase order" attachment a RAR archive containing a malicious executable.
Once executed, the malware loads its final payload directly into memory, avoiding disk-based detection. Researchers identified multiple variants of the campaign, each employing different packaging and execution methods while maintaining the same objective: silent deployment of VIP Keylogger to harvest sensitive data from browsers, email clients, chat applications, and file transfer tools.
### Stealthy Delivery and Evasion Tactics
The campaign employs advanced evasion techniques to bypass security measures:
- Steganography & Process Hollowing: In one variant, a .NET executable concealed two DLLs in its resource section. One DLL extracted the next stage, which then retrieved the final payload from a hidden PNG image. The malware used process hollowing launching a legitimate process in suspended mode, replacing its memory with malicious code, and resuming execution.
- Direct In-Memory Execution: Another variant stored an AES-encrypted payload in its `.data` section. After decryption, it disabled Windows security monitoring (AMSI and ETW) and loaded VIP Keylogger via the Common Language Runtime (CLR), evading defensive checks.
The campaign appears linked to a malware-as-a-service (MaaS) model, with some payload features disabled or configurable, suggesting customization for different buyers.
### Broad Credential Theft Capabilities
VIP Keylogger targets a wide range of sensitive data, including:
- Saved logins, cookies, credit card details, autofill data, download history, and browsing URLs from Chromium-based browsers (Chrome, Edge, Brave, Opera, Vivaldi).
- Firefox-based browser credentials via the `PK11SDR_Decrypt` API from `nss3.dll`.
- Exfiltration via multiple channels, including FTP, SMTP (port 587), Telegram, Discord, and HTTP POST.
### Indicators of Compromise (IoCs)
Researchers shared the following hashes linked to the campaign:
- D1DF5D64C430B79F7E0E382521E96A14 (MD5) – Trojan (700000211)
- E7C42F2D0FF38F1B9F51DC5D745418F5 (MD5) – Trojan (006d73c21)
- EA72845A790DA66A7870DA4DA8924EB3 (MD5) – Trojan (005d5f371)
- 694C313B660123F393332C2F0F7072B5 (MD5) – Spyware (004bf6371)
The campaign underscores how threat actors combine phishing, steganography, and fileless execution to create scalable, hard-to-detect credential theft operations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
746
JANUARY 2026
746
DECEMBER 2025
746
NOVEMBER 2025
746
OCTOBER 2025
746
SEPTEMBER 2025
746
AUGUST 2025
746
JULY 2025
746
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Viper ??
What was Viper's A.I Rankiteo Cyber Score in May 2026 ??
What was Viper's A.I Rankiteo Cyber Score in April 2026 ??
What was Viper's A.I Rankiteo Cyber Score in March 2026 ??
What was Viper's A.I Rankiteo Cyber Score in February 2026 ??
What was Viper's A.I Rankiteo Cyber Score in January 2026 ??
What was Viper's A.I Rankiteo Cyber Score in December 2025 ??
What was Viper's A.I Rankiteo Cyber Score in November 2025 ??
What was Viper's A.I Rankiteo Cyber Score in October 2025 ??
What was Viper's A.I Rankiteo Cyber Score in September 2025 ??
What was Viper's A.I Rankiteo Cyber Score in August 2025 ??
What was Viper's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Viper's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Viper ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Viper's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?