aksiyononline.best: a server handing out PowerShell stubs for MassLogger and VIP Keylogger, and what to do if a script fetched them

aksiyononline.best is a web address that URLhaus lists thirteen times for PowerShell and JavaScript files named Crypted.ps1 and secured_stub.ps1, three of them tagged MassLogger and one VIPKeylogger, keyloggers that steal passwords from Windows PCs. A file like that does nothing on its own; it is a stage that a script already running on a PC fetches.

If you only saw the name in a log, nothing is proven. If something on your PC may have fetched these files, treat every saved password as stolen: change them from another device, then scan and clean or reset Windows.

Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

If a script, attachment or program that downloads PowerShell files from aksiyononline.best keeps coming back after uninstalling, a scan can find what reinstalls it.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove aksiyononline.best (MassLogger, VIP Keylogger PowerShell stubs) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Table of thirteen URLhaus entries for aksiyononline.best: eleven PowerShell files named Crypted.ps1 or secured_stub.ps1, one JavaScript file, one PowerShell file from 30 September; one entry online, tagged MassLogger and VIPKeylogger
The thirteen URLhaus entries for aksiyononline.best that we read on 6 October 2026, with their main tags. Only masabikk6/secured_stub.ps1 was still marked online. Our own check was a plain request to the home page, so this table of reports, not a screenshot of the site, is the main evidence.

Aksiyononline.best (MassLogger, VIP Keylogger PowerShell stubs): summary

TypeA malware server: URLhaus lists PowerShell and JavaScript loader files, three tagged MassLogger and one VIPKeylogger (keyloggers for Windows)
RiskHigh if a script on your PC fetched its files: saved passwords, cookies, cards, keystrokes and Wi-Fi passwords may be taken. Low if you only saw the name
SymptomsOften none. A script window after opening an attachment, an unknown logon script or task, or aspnet_compiler.exe running with no reason are the signs in the reports
How to get rid of itChange passwords from another device, run Microsoft Defender Offline, remove the startup entries, and reset Windows if you are not sure
Our check (6 October 2026)One plain request to the home page: HTTP 200, a placeholder page behind Cloudflare. A quiet home page clears nothing; the rating comes from URLhaus
Running since / first seenDomain registered 28 July 2026; first file reported 30 September 2026, twelve more on 6 October 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformWindows. Nothing we read says Mac or phones are affected
Detection namesNo Microsoft name is known for the files on this server, because we did not open them. For MassLogger builds in general Microsoft uses Trojan:MSIL/Masslogger!MTB
NameAksiyononline.best
Domain registered28 July 2026
Evidence13 write-ups by security sites; details still limited
First seen30 September 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked6 October 2026

Facts checked on 6 October 2026 against the URLhaus data for aksiyononline.best held in our database, RDAP, one plain request of our own from our server (no browser, no clicks), and published reports by Microsoft, Mandiant, Splunk, Seqrite, Fortinet and the FTC. We did not download the files and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.

What aksiyononline.best is, and what we know about it

aksiyononline.best is not a program on your PC. It is a web address that the abuse.ch project URLhaus lists as a place where malware was handed out: PowerShell scripts named Crypted.ps1 and secured_stub.ps1, and one JavaScript file. Three of the thirteen entries are tagged MassLogger and one VIPKeylogger, Windows keyloggers that steal saved passwords.

We found no public write-up of this one address, so this page sets out what URLhaus shows, what our own request returned, and what security vendors have published about these families and how they are delivered.

  1. 1

    What URLhaus lists

    Thirteen file addresses on aksiyononline.best, each in its own folder with a short made up name such as masabikk6, princee255, frndmass1 or cattt25. One was added on 30 September 2026. The other twelve were added within about two minutes on the morning of 6 October 2026, between 08:12 and 08:14 UTC. Every entry carries the threat label malware_download and the reporter abuse_ch.

  2. 2

    What the file names say

    Eleven of the files end in .ps1, the ending of a Windows PowerShell script. Six are called Crypted.ps1 and six secured_stub.ps1 (one of those is the September entry). The thirteenth is a JavaScript file with a long random name in the folder cattt25/cat. A stub, in this trade, is the small piece that unpacks and starts the real malware. Crypted is the word sellers of so called crypters use for malware wrapped to get past antivirus. The names fit that use; they do not prove what is inside.

  3. 3

    What the tags mean

    powershell, ps1, js and ascii describe the file type: plain text scripts. opendir means the folders could be listed by anyone, which is how so many files were found together. MassLogger is on three entries: the JavaScript file, masabikk4/secured_stub.ps1 and masabikk6/secured_stub.ps1. VIPKeylogger is on one: masabikk6/secured_stub.ps1, the only file still marked online when we read the data.

  4. 4

    What we could not confirm

    We did not download any of the files, so we cannot tell you exactly what each script does, which keylogger build it ends in, or where that build sends what it takes. URLhaus tags are the reporter's labels, not a proof. We also do not know which email or file makes a victim's PC ask for these scripts: that first step happens on the victim's side and is not visible from the server.

  5. 5

    What this means for you

    If you only saw the name in a firewall log, a DNS log or a blocked request, you are not infected by that alone. The risk is for a Windows PC where a script or attachment already ran and asked for one of these files. Nobody browses to a folder like masabikk6 by hand.

Kind of threat
A server that hands out PowerShell and JavaScript loader files; three are tagged MassLogger and one VIPKeylogger, keyloggers and password stealers for Windows
Where the files are
hxxps://aksiyononline[.]best/<folder>/Crypted.ps1 or secured_stub.ps1, plus one .js file in cattt25/cat
Domain registered
28 July 2026 through Spaceship, Inc., status active (RDAP, read 6 October 2026)
URLhaus entries
13 file addresses: 1 added 30 September 2026, 12 added 6 October 2026; 1 online and 12 offline when we read the data
Home page
Answered our plain request with HTTP 200 and a page titled Application placeholder, served through Cloudflare
Platform
Windows. PowerShell stubs, MassLogger and VIP Keylogger are Windows programs; nothing we read says Mac, iPhone or Android are affected

What aksiyononline.best (MassLogger, VIP Keylogger PowerShell stubs) does on an infected PC

What we checked on 6 October 2026, and what we could not

Our server sent one plain request to the home page of aksiyononline.best on 6 October 2026. It was not a browser visit: nothing was clicked, no scripts on the page ran, and no screenshot was taken. The answer was an ordinary page titled Application placeholder. That clears nothing, because the reported files sit in subfolders, not on the home page.

Our check, 6 October 2026

  • The home page answeredHTTP status 200 with the title Application placeholder and no redirect. That is the kind of empty default page a freshly set up web host shows. A loader server does not need a real front page, so an empty one is normal for this kind of host and is not a sign of safety.
  • Served through CloudflareThe server header said cloudflare. Cloudflare sits in front of many millions of sites and hides the real hosting address. It tells you nothing about who runs this one.
  • Notification requestThe page text did not mention the browser notification API. Our check was a plain request, so scripts that only run in a browser would not show.
  • URLhaus listingThirteen script files tagged malware_download; three tagged MassLogger, one tagged VIPKeylogger; masabikk6/secured_stub.ps1 still online in our copy of the data on 6 October 2026.
  • The files themselvesWe did not request or open any of the listed scripts. We cannot tell you what they contain beyond the names and tags.

Dangerous: treat it as a malware server A quiet home page proves nothing. The danger rating comes from the thirteen URLhaus reports and their tags, not from our request. Do not request files from this address and do not run anything that does.

What happened to aksiyononline.best, from registration to our check

The domain is about ten weeks old. The dates below come from RDAP and from the URLhaus data we hold; the times are UTC.

  1. 28 July 2026

    The domain is registered

    RDAP shows aksiyononline.best registered on 28 July 2026 through Spaceship, Inc. The name reads like a Turkish news or shopping title (aksiyon is Turkish for action), but we found nothing that ties it to any real business, and we do not draw conclusions from the name.

  2. 30 September 2026

    The first file is reported

    At 15:00 UTC abuse.ch adds mrmasabikfrnd/secured_stub.ps1, tagged ascii, opendir, powershell and ps1. It is offline by the time we read the data.

  3. 6 October 2026, 08:12 UTC

    The one file still online

    masabikk6/secured_stub.ps1 is added with the tags MassLogger and VIPKeylogger as well as opendir and powershell. It is the only one of the thirteen still marked online when we read the data later that day.

  4. 6 October 2026, 08:13 to 08:14 UTC

    Eleven more files in two minutes

    Ten more PowerShell files and one JavaScript file are added, each in its own folder. masabikk4/secured_stub.ps1 and the JavaScript file in cattt25/cat are tagged MassLogger. All eleven are offline when we read the data.

    Table of the thirteen URLhaus entries for aksiyononline.best with dates, folder and file names, online status and main tags
    All thirteen URLhaus entries for aksiyononline.best on 6 October 2026. The folder names change; the two file names repeat.
  5. 6 October 2026, evening

    Our check

    Our server's plain request to the home page gets HTTP 200 and a placeholder page through Cloudflare.

What the pattern suggests, and what it does not: many folders with names like masabik, frndmass and prince, each holding the same two file names, look like one operator preparing copies of the same stub for several buyers or campaigns, then pulling most of them again within hours. That is our reading of the names and dates, not something any report says.

How a PowerShell stub turns into a keylogger

A .ps1 file on a server cannot hurt you by sitting there. It works only when something already running on the PC downloads it and hands it to PowerShell. We did not see the files on aksiyononline.best; this is how Splunk and Seqrite describe the chain for VIP Keylogger.

Five steps: a phishing email, a first VBS, JS or BAT script, a PowerShell stage such as Crypted.ps1, a loader decoded in memory, and MassLogger or VIP Keylogger running inside a trusted Windows process
The chain in five steps as the vendors describe it for VIP Keylogger. Step 3 is the kind of file URLhaus lists on aksiyononline.best; the first step for this server is not known.
  1. 1

    A lure arrives by email

    Splunk (13 May 2026) describes phishing lures such as fake bank payment notices. Seqrite's VIP Keylogger white paper describes an email posing as a buyer, with an RTF document named like an order inquiry. Opening the document makes it connect to a web address and fetch a script.

  2. 2

    A first script runs

    Splunk reviewed more than 200 loader samples from March and April 2026 and found VBS, JavaScript and batch files with heavy junk code. In Seqrite's chain a first VBScript decrypts an address and downloads a second VBScript, which then starts PowerShell.

  3. 3

    PowerShell fetches the next stage

    This is where a file like Crypted.ps1 or secured_stub.ps1 fits. Splunk found the decoded PowerShell script being written into a user environment variable and run from there, so no script file needs to stay on the disk.

  4. 4

    The loader is pulled out of hiding

    Splunk describes PNG pictures whose hidden part starts at a marker and is decoded from reversed base64. Seqrite describes picture files with the markers BASE64_START and BASE64_END around a .NET library. The library is loaded straight into memory.

  5. 5

    The keylogger runs inside a trusted program

    Splunk saw the final payload injected into aspnet_compiler.exe; Seqrite saw dxdiag.exe used for process hollowing, where a genuine Windows program is started and its contents replaced. In Task Manager the keylogger then wears a Microsoft name.

Because every stage after the first is a script or a file loaded into memory, there may be very little to find on the disk afterwards. That is why the advice on this page starts with your accounts, not with a file hunt.

What MassLogger and VIP Keylogger are

Both names stand for commercial keyloggers written in .NET for Windows. They are sold to criminals, not written by one group, so the same family turns up behind many different servers. Vendors treat VIP Keylogger as a close relative of Snake Keylogger, and URLhaus put the MassLogger and VIPKeylogger tags on the same file here.

Sources: Mandiant, Splunk, Seqrite, Fortinet FortiGuard Labs and Microsoft, all read 6 October 2026.
QuestionWhat the sources saySource
What is MassLogger?A .NET credential stealer with a keylogger, analysed by Mandiant in 2020. Its configuration switches on browser password recovery, keylogging, clipboard and screenshotsMandiant (Google Cloud), 6 August 2020
What is VIP Keylogger?A modular keylogger and stealer delivered through phishing; Seqrite calls it similar to Snake KeyloggerSplunk, 13 May 2026; Seqrite white paper
And Snake Keylogger?A subscription keylogger also called 404 Keylogger or KrakenKeylogger, sold since at least 2020 and still active in 2024Fortinet FortiGuard Labs, 28 August 2024
How does it send data out?MassLogger: email over SMTP, FTP or an HTTP panel. Snake: FTP, email or a Telegram bot. VIP Keylogger: HTTP servers and a Telegram botMandiant; Fortinet; Splunk
How does it stay?VIP Keylogger: the UserInitMprLogonScript registry value, which runs at every sign in (Splunk). Snake: a scheduled task (Fortinet). Seqrite's loader had options for a startup task and a startup registry entrySplunk; Fortinet; Seqrite
How does it hide?Code loaded only in memory, process hollowing into trusted Windows programs, and in MassLogger's case code rewritten at run time to frustrate analysisSplunk; Seqrite; Mandiant
What does Microsoft call it?Trojan:MSIL/Masslogger!MTB, alert level severe. MTB means caught by behaviour, not by a fixed signatureMicrosoft Security Intelligence
Which build is this server's?Not known. URLhaus gives the tags MassLogger and VIPKeylogger; we did not open the filesNot available

What aksiyononline.best (MassLogger, VIP Keylogger PowerShell stubs) can steal or download

What these keyloggers take from a Windows PC

A keylogger of this kind works on its own once it runs: it collects and sends without anyone watching. Each item below is named by at least one of the sources; which ones a given build collects depends on how the buyer set it up.

Reported as collected

  • Every key you type
  • Saved browser passwords
  • Browser cookies
  • Autofill entries
  • Saved card names, numbers and expiry dates
  • Email client logins (Outlook, Thunderbird, Foxmail)
  • Discord tokens
  • Telegram data
  • Wi-Fi passwords
  • Clipboard contents
  • Screenshots
  • PC name, IP address and location
Sources: Splunk (13 May 2026), Seqrite, Mandiant (6 August 2020) and Fortinet (28 August 2024), read 6 October 2026.
DataDetailSource
KeystrokesRecorded in the background while you typeMandiant; Splunk; Seqrite; Fortinet
Browser dataLogins, cookies and autofill from more than 40 browsers, including Chrome, Edge, Firefox, Opera, Brave and Yandex; Seqrite adds saved card details and top visited sitesSplunk; Seqrite
Mail and chatOutlook credentials from the registry, Thunderbird, Foxmail, Pidgin, Discord tokens and Telegram dataSplunk; Seqrite; Mandiant
Wi-FiSaved Wi-Fi passwords read with the netsh commandSplunk
ClipboardCopied text; Splunk saw crypto wallet addresses in the clipboard replaced with the attacker'sSplunk; Seqrite
ScreenScreenshots saved and sentSplunk; Seqrite; Mandiant
Your PCComputer name, IP address, location and time zoneFortinet

What this can cost you

Seeing the name costs nothing. The risks below apply to a Windows PC where a script fetched one of these files and the keylogger then ran.

  • High

    Passwords and accounts

    Saved browser passwords go out in the first minutes, and every new password typed afterwards is recorded too. Changing passwords on the infected PC hands the new ones over.

  • High

    Logged in sessions

    Stolen cookies can let someone use an account that is already signed in, sometimes without the password or the second sign in step. Signing out of all sessions matters as much as the new password.

  • High

    Cards and crypto

    Seqrite lists saved card details; Splunk describes clipboard swapping of wallet addresses, so a payment you paste can go to the wrong wallet. Crypto sent that way cannot be reversed.

  • Medium

    Work email and company access

    The lures are business themed (orders, payments), and Outlook credentials are on every list. A work mailbox taken this way is often used for invoice fraud against your contacts.

  • Medium

    Your Wi-Fi and other devices

    Saved Wi-Fi passwords are taken, so the network itself is known to the attacker.

  • Low

    Nothing, if you only saw the name

    A name in a block list, a log or a warning is not an infection.

What you may notice, and what you may not

These keyloggers are built to stay quiet. The signs below come from the sources and from what they imply; none is certain, and most victims notice nothing until an account is misused.

SignWhat the reports show
A PowerShell or script window that flashed after opening an attachmentEvery chain described starts with a script; a brief console window is often the only visible moment
A Microsoft program running when it should notSplunk names aspnet_compiler.exe and Seqrite names dxdiag.exe as hiding places. They are real Windows programs, so one running with no reason, or using the network, is worth a look
An unknown logon script or scheduled taskSplunk saw UserInitMprLogonScript set under HKEY_CURRENT_USER\Environment; Fortinet saw a scheduled task. Both start the malware again at sign in
A very long entry in your environment variablesSplunk found the PowerShell stage stored in a user environment variable and suggests watching for values over 2,000 characters
A Defender detectionMicrosoft's family name is Trojan:MSIL/Masslogger!MTB
Accounts acting strangelyNew sign ins, password reset emails, mail forwarding rules or messages you did not send. These follow from stolen logins
Nothing at allMemory only loading is the point of the chain

How to check the PC for aksiyononline.best (MassLogger, VIP Keylogger PowerShell stubs)

How a person ends up asking for these files

Nobody visits aksiyononline.best on purpose. The request comes from a script on the PC, so the real question is how that script got there. We cannot say for this server; the routes below are the ones the vendors found for the same families.

  1. 1

    A business email with an attachment

    Seqrite describes an order inquiry with an RTF file; Fortinet describes an Excel file called swift copy claiming money was sent to you; Splunk describes fake bank payment alerts. Opening the attachment is the step that starts it.

  2. 2

    A script inside an archive

    Splunk's loaders are VBS, JavaScript and batch files. They usually arrive packed in an archive or attachment and look like a document if file endings are hidden in File Explorer.

  3. 3

    Cracked software

    Seqrite notes that the same kind of keylogger is also spread through software cracks.

Check your PC before you delete anything

Start with the question that matters: did something on this PC contact aksiyononline.best, or did you open an unexpected attachment, script or archive in the last weeks? If you saw the name in a firewall or DNS log from your own network, the device that asked is the one to check. If the answer is yes or you are not sure, do the checks below. None of them deletes anything.

While you check, stop using the PC for banking, email, work or crypto. Use a phone or another computer for anything that needs a password.

  1. 1

    Disconnect first

    Turn off Wi-Fi or unplug the network cable. A keylogger needs the connection to send what it took.

  2. 2

    Find which device asked for the address

    If you came here from a log, a router page or an alert, note the device and the time. Only that device is in question.

  3. 3

    Open Protection history

    In Windows Security > Virus & threat protection > Protection history, look for Trojan:MSIL/Masslogger!MTB, any detection with PowerShell or a script in its name, or anything blocked around the time of the first contact.

  4. 4

    Look at what starts with Windows

    Open Settings > Apps > Startup and look for names you did not install. Then open Task Scheduler and look in Task Scheduler Library for tasks with odd names that run PowerShell, wscript or a program from a user folder. Write down what you find; do not delete yet.

  5. 5

    Look for the logon script value

    Splunk found VIP Keylogger in the value UserInitMprLogonScript under HKEY_CURRENT_USER\Environment. Open Registry Editor, go to that key and see whether the value exists. On most home PCs it does not. While you are there, look for any other value with a very long text.

  6. 6

    Look for trusted programs that should not be running

    Open Task Manager and look for aspnet_compiler.exe, dxdiag.exe, RegSvcs.exe or a PowerShell process running with no reason. Right click and choose Open file location to see where it lives. Their presence is not proof, and their absence does not clear the PC.

  7. 7

    Check your accounts from another device

    Look at the sign in activity of your email, bank, work and exchange accounts, and at mail forwarding rules. This is faster and more telling than any file check.

  8. 8

    A scan helps, but it does not clear the PC

    A scan with Microsoft Defender or another product can find known files. Treat a clean result as one data point. No vendor publishes a removal procedure for this server's files and we did not infect a PC, so the order of the plan is our judgement from Microsoft's pages and the vendor reports, not a tested result.

How to remove aksiyononline.best (MassLogger, VIP Keylogger PowerShell stubs)

How to remove aksiyononline.best

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to aksiyononline.best or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever aksiyononline.best installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

If you use a Mac, an iPhone or an Android phone

The file types, the tags and every source we read describe a Windows threat. We found nothing that says the files on aksiyononline.best affect anything else.

Your deviceWhat we knowWhat to do
MacPowerShell stubs, VBS loaders and .NET keyloggers are built for WindowsNothing to remove for this threat. Do not follow the Windows steps on a Mac
iPhone or iPadNo source describes these families on iOSNothing to remove. Change any password you typed on the Windows PC
AndroidNo source mentions itNothing to remove for this threat; change passwords if the Windows PC was used for them

After removal: passwords, accounts and prevention

After a clean PC: protect what was taken

The PC is one half. The other half is everything saved or typed on it while the keylogger ran. The order matters: another device first, then the PC.

Five steps in order: disconnect the PC, change passwords from another device, run a Microsoft Defender Offline scan, check what starts with Windows, reset Windows if unsure
The order of actions if a script on your PC reached aksiyononline.best. Steps follow Microsoft's pages; we did not test them on an infected PC.
  1. 1

    Change passwords from a clean device

    Start with email, because it resets everything else, then bank, work, cloud storage, Discord, Telegram and crypto. Every password saved in a browser on the PC should be treated as known.

  2. 2

    Sign out other sessions and turn on two step sign in

    The FTC says to sign out of all devices so anyone else is forced out, and to turn on two factor authentication so a password alone is not enough. This matters here because stolen cookies can keep a session open. Check recovery email, phone and mail forwarding rules.

  3. 3

    Call your bank if cards were saved

    Seqrite lists saved card details among the data taken. Ask the bank to block and replace any card that was stored in a browser on the PC.

  4. 4

    Move crypto if a wallet was on the PC

    Create a new wallet and recovery phrase on a clean device and move the funds. Check the receiving address character by character, because clipboard swapping is part of VIP Keylogger.

  5. 5

    Change the Wi-Fi password

    Splunk lists Wi-Fi passwords. Change the router's Wi-Fi password and the router admin password.

  6. 6

    Run Microsoft Defender Offline

    Microsoft says to open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Antivirus (offline scan) and select Scan now. The PC restarts and scans before Windows loads, which makes it harder for malware to hide; results appear in Protection history.

  7. 7

    Remove what the check found, with care

    If a task, a startup entry or the UserInitMprLogonScript value clearly belongs to the malware, delete it. If you cannot tell, do not guess: the safe answer is the reset below.

  8. 8

    If you are not sure, reset Windows

    Microsoft puts the reset at Settings > System > Recovery > Reset this PC. Keep my files removes apps and settings but keeps personal files; Remove everything wipes the PC. Back up documents first and have your BitLocker recovery key ready if BitLocker is on. For a PC where a keylogger ran, the full wipe is the answer that does not depend on finding every piece.

  9. 9

    Restore only documents by hand

    Copy back documents and photos, not programs or scripts, and not a full system image from after the first contact.

  10. 10

    Watch your accounts for weeks

    Turn on login and payment alerts. The FTC says to report stolen personal information at IdentityTheft.gov, which gives a recovery plan. If a work account was on the PC, tell your IT team the same day.

Keep a PC out of this kind of chain

The PowerShell stub is the middle of the chain. Every vendor write-up we read starts earlier, with an attachment or script that a person opened.

Do

  • Treat an unexpected order, invoice or payment notice with an attachment as an attack until the sender confirms it another way.
  • Show file endings in File Explorer so a .vbs, .js or .bat file posing as a document is visible.
  • Keep Windows and Microsoft Defender updated.
  • Use a password manager instead of the browser's saved passwords, and two step sign in everywhere.
  • Check a pasted crypto address before you send.
  • Keep a backup of documents on a disk that you unplug.

Don't

  • Do not open RTF, Office or archive attachments you did not expect, even from a known name.
  • Do not run cracked programs or tools from sites that promise free versions of paid software.
  • Do not allow a script or a PowerShell window to run because a document asks you to.
  • Do not change your passwords on the PC you suspect.
  • Do not take a quiet home page or a clean scan as proof that you are safe.

Questions about aksiyononline.best (MassLogger, VIP Keylogger PowerShell stubs)

What is aksiyononline.best?

It is a web address that URLhaus, the malware tracking project run by abuse.ch, lists for thirteen script files: eleven PowerShell files named Crypted.ps1 or secured_stub.ps1 and one JavaScript file, plus one more PowerShell file from 30 September.

Three entries are tagged MassLogger and one VIPKeylogger. It is not a program on your PC and not a site anyone is meant to visit. We did not download the files.

Is aksiyononline.best safe to open?

No. Do not request files from it, and do not run anything that does. Our plain request to the home page got a placeholder page, which proves nothing: the reported files sit in subfolders, and a loader server rarely needs a real front page. The rating comes from the URLhaus reports and their tags.

What is secured_stub.ps1 or Crypted.ps1?

Both are PowerShell scripts, the .ps1 ending is Windows PowerShell. A stub is the small piece that unpacks and starts the real malware, and crypted means wrapped to get past antivirus. In the chains Splunk and Seqrite describe, a script like this is fetched by an earlier VBS, JavaScript or batch file, then loads the keylogger into memory.

What are MassLogger and VIP Keylogger?

Commercial .NET keyloggers for Windows sold to criminals. Mandiant describes MassLogger stealing browser and app passwords, keystrokes, clipboard and screenshots and sending them by email, FTP or a web panel.

Splunk describes VIP Keylogger taking browser logins, cookies, Wi-Fi passwords, Discord tokens and Outlook credentials and sending them to servers and a Telegram bot. Seqrite calls VIP Keylogger similar to Snake Keylogger.

I saw aksiyononline.best in my firewall or DNS log. Am I infected?

Not necessarily, and the name alone proves nothing. It does mean a device on your network asked for it, and people do not do that by hand. Find which device it was, disconnect it, and run the checks on this page:

  • Protection history
  • startup apps
  • Task Scheduler
  • the UserInitMprLogonScript value
  • a Microsoft Defender Offline scan

Change passwords from another device.

How do I remove MassLogger or VIP Keylogger from Windows?

Change your passwords from another device first. Then run a Microsoft Defender Offline scan from Windows Security, check startup apps, Task Scheduler and the UserInitMprLogonScript value under HKEY_CURRENT_USER\Environment, and delete what you can tie to the malware.

If you are not sure, reset Windows with Remove everything and restore only documents. We followed Microsoft's pages and did not test the steps on an infected PC.

Were my passwords stolen?

If the keylogger ran, assume yes. These families read saved browser passwords, cookies and autofill right away and record what you type afterwards.

Change every password that was saved or typed on the PC, from another device, sign out of all sessions and turn on two step sign in. Ask your bank to replace cards that were saved in the browser.

Does aksiyononline.best affect Mac, iPhone or Android?

We found nothing that says so. PowerShell stubs and .NET keyloggers are Windows threats, and every source we read describes Windows.

On a Mac, iPhone or Android phone there is nothing to remove for this threat, but change any password that was used on the affected Windows PC. If you are unsure which device made the request, check your router or DNS log for the device name first.

Will resetting Windows remove it, and are my accounts safe afterwards?

A reset with Remove everything wipes the scripts, the startup entries and the keylogger, which does not depend on finding every piece. It does not undo what was already sent.

Passwords, cookies, card details and Wi-Fi passwords that were taken stay exposed until you change them from another device. Restore documents by hand, not a full system image.

Will Fortect remove aksiyononline.best?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For aksiyononline.best, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove porterneuman.mx: PowerShell and JavaScript files tied to the AveMaria remote access trojan, and what to do

porterneuman.mx is a web address where URLhaus found five script files in a WordPress plugin folder on 30 September 2026: four PowerShell stubs and one JavaScript file. One stub is tagged AveMariaRAT, a remote access...TrojansHigh riskUgnius Kiguolis ·

Remove Memz virus

Memz virus is the custom-made trojan that overwrites Windows boot sequence with Nyan Cat meme animation Memz virus is the trojan originally created by Leurak as viewer-made malware forTrojansHigh riskLucia Danes ·

Remove qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran

qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger, two keyloggers that steal passwords...TrojansHigh riskUgnius Kiguolis ·

Remove www.beinke-aufzuege.de: a hacked website hosting FormBook PowerShell stubs, and what to do if a script fetched them

www.beinke-aufzuege.de is the address of a German website that URLhaus lists for four PowerShell files tagged Formbook, a password stealer for Windows, hidden in random folders inside the site's own Joomla media...TrojansHigh riskUgnius Kiguolis ·

Questions and experiences: aksiyononline.best (MassLogger, VIP Keylogger PowerShell stubs)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year