cablewireltd.site: a Windows VIP Keylogger host serving Crypted.ps1 PowerShell files, and what to do if one ran

cablewireltd.site is a web address that URLhaus lists nine times in September 2026 for malware files: seven PowerShell scripts named Crypted.ps1 and two JavaScript loaders, three of them tagged VIPKeylogger, a password and keystroke stealer for Windows.

The domain was registered on 21 September and is now on server hold, so it no longer answers. If you only saw the name in a log, nothing is proven. If a script on your PC fetched these files, change your passwords from another device first, then check and clean or reset Windows.

Facts checked October 10, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

An automatic scan checks installed programs, startup items and browser extensions for anything that came with a script file or a PowerShell command that fetched files from cablewireltd.site.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove cablewireltd.site (VIP Keylogger, PowerShell stages) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Table of nine URLhaus entries for cablewireltd.site: seven Crypted.ps1 PowerShell files and two JavaScript files, three tagged VIPKeylogger, all offline
The nine URLhaus entries for cablewireltd.site that we read on 10 October 2026. Our server could not resolve the name, so this table of reports, not a screenshot of the site, is the main evidence.

Cablewireltd.site (VIP Keylogger, PowerShell stages): summary

TypeA malware host: URLhaus lists seven Crypted.ps1 PowerShell files and two JavaScript loaders, three tagged VIPKeylogger, an information stealer for Windows
RiskHigh if a script on your PC fetched its files: passwords, cookies, cards, Wi-Fi keys and keystrokes may be taken. Low if you only saw the name
SymptomsOften none. Browsers closing by themselves, a UserInitMprLogonScript value in HKCU\Environment, or account alerts are the signs in the reports
How to get rid of itChange passwords and sign out sessions from another device, check the logon script and startup entries, run Microsoft Defender Offline, reset Windows if unsure
Our check (10 October 2026)The name did not resolve (ENOTFOUND) and RDAP shows server hold. An offline host clears nothing; the rating comes from URLhaus
Running since / first seenDomain registered 21 September 2026; files reported on 23 and 24 September 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformWindows. Nothing we read says Mac or phones are affected
Detection namesNo Microsoft detection name is known for these files, because we did not open them. Defender may show names that contain VIPKeylogger, Snake or PowerShell
NameCablewireltd.site
Domain registered21 September 2026
Evidence9 write-ups by security sites; details still limited
First seen23 September 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked10 October 2026

Facts checked on 10 October 2026 against the URLhaus data for cablewireltd.site held in our database, the RDAP record, one plain request from our server (the name did not resolve), and published analyses by Splunk and Seqrite, plus Microsoft's pages on Defender Offline and recovery.

We did not download the files and infected no PC; the removal steps follow Microsoft's pages and the researchers' findings and were not tried on a live infection.

What cablewireltd.site is, and what we know about it

cablewireltd.site is not a program on your PC. It is a web address where, according to the abuse.ch project URLhaus, nine malware files were hosted in September 2026: seven PowerShell scripts all called Crypted.ps1 and two JavaScript files with long random names. Three of the PowerShell files are tagged VIPKeylogger, a password and keystroke stealer for Windows. We found no public write-up of this one address, so this page sets out what URLhaus lists, what our server saw, and what researchers have published about VIP Keylogger and its loaders.

  1. 1

    What URLhaus lists

    Nine file addresses on cablewireltd.site, each inside its own folder. The folders carry names such as masabik23, mrprince, prince23, masfrnd and frndmass244. Seven hold a file named Crypted.ps1; one folder, ppriincefil21, holds two .js files. All nine were added between 23 and 24 September 2026, all carry the label malware_download and the reporter is abuse_ch.

  2. 2

    What the tags mean

    ps1 and powershell mean the file is a PowerShell script, a plain text program that Windows can run. js means JavaScript, which Windows can run outside a browser when a person opens the file. ascii means the content is readable text. opendir means the folder could be listed by anyone who asked, which is how so many files were found at once. VIPKeylogger is the name of the malware family the reporter linked to three files.

  3. 3

    What we could not confirm

    We did not download any of the files, so we cannot say which VIP Keylogger build they lead to, where it sends stolen data, or whether the six files without the family tag do the same thing. We also do not know which email or download made a victim's PC ask for these files.

  4. 4

    What this means for you

    If you only saw the name in a firewall log, a DNS log or a browser warning, that alone is not an infection. The risk is for a Windows PC where a script was opened and went to fetch one of these files. A normal visitor has no reason to request a file called Crypted.ps1.

Kind of threat
A malware host serving PowerShell and JavaScript stages; three files tagged VIPKeylogger, an information stealer for Windows
Where the files were
hxxps://cablewireltd[.]site/<folder>/Crypted.ps1 and two .js files in /ppriincefil21/
Domain registered
21 September 2026 through Spaceship, Inc.; the registry status now shows server hold (RDAP, read 10 October 2026)
URLhaus entries
9 file addresses added on 23 and 24 September 2026; all 9 offline when we read our copy of the data
Delivery trick
Script stages that fetch further code; VIP Keylogger chains hide the last parts in image files. The first step on a victim's PC is not known
Platform
Windows. PowerShell stages and the .NET stealer are Windows software. Nothing we read says Mac, iPhone or Android are affected

What cablewireltd.site (VIP Keylogger, PowerShell stages) does on an infected PC

What we checked on 10 October 2026, and what we could not

Our server asked for cablewireltd.site once on 10 October 2026 with a plain request. The name did not resolve at all: the answer was getaddrinfo ENOTFOUND, which means no DNS server gave an address for it. That fits the registry status server hold, which takes a domain out of the DNS. It clears nothing about the files that were served in September.

Our check, 10 October 2026

  • The name did not resolvegetaddrinfo ENOTFOUND cablewireltd.site. There was no server to talk to, so no page, no file and no redirect could be seen.
  • Server hold on the domainRDAP lists the status server hold, together with client transfer prohibited and client update prohibited. Server hold is set at registry level and usually follows an abuse report. It does not tell us who set it or why.
  • Why an offline host is not a clean resultThe operators can move the same files to a new name within hours. A script already on a PC may also try other addresses. A dead name today says nothing about a PC that fetched a file in September.
  • URLhaus listingNine malware_download entries, seven PowerShell files and two JavaScript files, three tagged VIPKeylogger; all offline in our copy of the data.
  • The files themselvesWe did not download or open any file. What each one contained is not confirmed by us.

Dangerous: treat it as a malware host The name no longer answers, so our check could not see anything. The rating comes from the nine URLhaus reports and their tags, and from what researchers publish about VIP Keylogger. If anything on your PC contacted this address, follow the steps below.

What happened to cablewireltd.site, from registration to our check

The whole life of this address fits into three days of activity and a quick shutdown. The dates come from RDAP and from the URLhaus data we hold; the times are UTC.

  1. 21 September 2026

    The domain is registered

    RDAP shows cablewireltd.site registered on 21 September 2026 at about 12:18 UTC through Spaceship, Inc. The name sounds like a cable and wire company, a common way to make a malware host look like a business.

  2. 23 September 2026, morning

    Five files are reported

    At about 08:09 and 08:10 UTC abuse.ch adds Crypted.ps1 in the folders masabik23, mrprince and masfrnd, and two long .js files in ppriincefil21. The file in masabik23 is tagged VIPKeylogger. All five carry the opendir tag, so the folders were open to browse.

  3. 23 September 2026, afternoon

    Three more PowerShell files

    At about 13:59 UTC Crypted.ps1 is added in prince23, masabik232 and massfrnd232. The one in masabik232 is tagged VIPKeylogger. The new folder names are the old ones with a number added, which looks like fresh batches.

  4. 24 September 2026

    The last file

    At about 13:41 UTC Crypted.ps1 in frndmass244 is added, again tagged VIPKeylogger. No later report exists in our data.

    Table of the nine URLhaus entries for cablewireltd.site with dates, folder paths, file type, open folder flag and VIPKeylogger tags
    The nine URLhaus entries for cablewireltd.site as we read them on 10 October 2026. Seven files share the name Crypted.ps1; only the folder changes.
  5. 10 October 2026

    Our check

    All nine entries are marked offline. The domain shows server hold in RDAP and our server cannot resolve the name.

Our reading of the pattern, not a statement from any report: folder names such as prince, mrprince, ppriincefil21 and masabik look like labels for different customers or campaigns of the same operator, each given its own copy of the stage. That is common when a loader is sold or shared, but we cannot prove it here.

What VIP Keylogger is

VIP Keylogger is a stealer written in .NET for Windows. Seqrite describes it as similar to Snake Keylogger, almost down to the variable names. Splunk's Threat Research Team studied more than 200 of its script loaders captured between March and April 2026 and published the results on 13 May 2026.

Sources: Splunk Threat Research Team (13 May 2026) and the Seqrite white paper on VIPKeyLogger, both read 10 October 2026.
QuestionWhat the sources saySource
What is it?A .NET keylogger and stealer that records keystrokes and takes saved logins, cookies, card data and moreSeqrite; Splunk
How does it arrive?Phishing emails posing as bank payment notices, purchase orders and shipping updates, with a script or document attachedSplunk; Seqrite
Which loaders?.vbs, .js and .bat files that start PowerShell; Seqrite also describes an RTF document that fetches a VBScriptSplunk; Seqrite
Where is the code hidden?In picture files. Splunk found two .png files with encoded data between markers; Seqrite found a picture with text between <<BASE64_START>> and <<BASE64_END>>Splunk; Seqrite
Where does it run?Inside a genuine Windows program. Splunk names aspnet_compiler.exe; Seqrite describes process hollowing into dxdiag.exeSplunk; Seqrite
How does it stay?Splunk saw the .bat loader write its path to the UserInitMprLogonScript value so it runs at every sign inSplunk
Where does data go?Telegram bots and the operators' own servers in Splunk's samples; an HTTP server in Seqrite'sSplunk; Seqrite
Which build is on this host?Not known. URLhaus gives only the tag; we did not open the filesNot available

How a Crypted.ps1 file fits into the infection chain

A file named Crypted.ps1 is a middle step. It does nothing unless something already on the PC downloads it and runs it. The two .js files on the same host are the kind of first step that does that. This is how the researchers describe the chain; we did not see it run from this host.

Five boxes showing a VIP Keylogger chain: an email, a script that runs, a Crypted.ps1 stage, a picture hiding code, and the keylogger inside a real .NET program
The VIP Keylogger chain in five steps as Splunk and Seqrite describe it. The red box marks the part cablewireltd.site served.
  1. 1

    A person opens an attachment

    Splunk's samples start with a .vbs, .js or .bat file sent as if it were an order or a payment notice. Seqrite's start with an RTF document named like an order inquiry. Double clicking the file is the step that starts everything.

  2. 2

    The script calls PowerShell

    Splunk found the .js loaders heavily obfuscated, pulling a PowerShell stager that is unpacked with base64 and AES. In the .vbs path, the PowerShell code is written into a user environment variable called INTERNAL_DB_CACHE, run, and deleted.

  3. 3

    The PowerShell stage downloads pictures

    Splunk's stager downloaded two .png files. The script looks for the markers IN- and -in1, swaps every # for A, reverses the text and decodes it. The result is not a picture at all but the next program.

  4. 4

    The stealer is loaded into a trusted program

    Splunk saw VIP Keylogger injected into aspnet_compiler.exe, a normal .NET tool. Seqrite saw a loader start dxdiag.exe and swap its contents. In Task Manager the stealer then wears a Microsoft name.

  5. 5

    The data leaves, and the file may vanish

    The stealer sends what it found to a Telegram bot or a server. Both reports describe it deleting itself afterwards. Splunk saw a hidden command prompt use choice.exe for a three second pause before the file is removed.

The nine files: what each name suggests, and what we do not know

File names and tags are weak evidence. The third column below is our reading and is marked as such.

Source: URLhaus data held in our database, read 10 October 2026. The names Crypted.ps1 and the folder labels are as reported; the third column is our interpretation.
File on cablewireltd.siteWhat URLhaus saysWhat it may be (our reading)
/masabik23/Crypted.ps1Offline; ascii, opendir, powershell, ps1, VIPKeylogger; 23 SepA PowerShell stage the reporter linked to VIP Keylogger
/masabik232/Crypted.ps1Offline; ascii, powershell, ps1, VIPKeylogger; 23 SepA newer copy for the same folder name with a number added; the only file without opendir
/frndmass244/Crypted.ps1Offline; opendir, powershell, VIPKeylogger; 24 SepThe last file reported, again tied to VIP Keylogger
/mrprince/, /prince23/, /masfrnd/, /massfrnd232/ Crypted.ps1Offline; ascii, opendir, powershell, ps1; 23 SepFour more stages with the same name. Probably the same kind of script; the content is unknown
/ppriincefil21/ two long .js filesOffline; ascii, js, opendir; 23 SepJavaScript loaders of the kind Splunk describes, which a person opens and which then fetch a PowerShell stage. Not confirmed

What cablewireltd.site (VIP Keylogger, PowerShell stages) can steal or download

What VIP Keylogger takes from a Windows PC

Unlike a remote access trojan, a stealer does not wait for a person to sit at your PC. It collects and sends in one go, often within a minute of starting. Everything below is named in the Splunk or Seqrite analysis.

Named in the reports

  • Every key you type
  • Saved browser passwords
  • Browser cookies
  • Saved credit card details
  • Autofill entries
  • Browsing and download history
  • Outlook, Thunderbird and Foxmail logins
  • Discord tokens
  • Telegram data
  • Wi-Fi passwords
  • Clipboard text
  • Screenshots
  • Your location and IP address
Sources: Splunk Threat Research Team (13 May 2026) and Seqrite's VIPKeyLogger white paper, read 10 October 2026.
DataDetailSource
BrowsersLogins, cookies, cards, autofill, top sites and downloads from Chrome, Edge, Firefox, Opera, Brave, Yandex, Vivaldi and many lesser known Chromium and Firefox based browsersSeqrite; Splunk
Email and chatOutlook passwords read from the registry, plus Thunderbird, Foxmail, PostBox, Pidgin and DiscordSplunk; Seqrite
Wi-FiSaved network passwords read in plain text with netsh wlan show profile ... key=clearSplunk
CryptoThe clipboard is watched for wallet addresses (Bitcoin, Ethereum, Monero, Litecoin and others) and a copied address is swapped for the attacker'sSplunk
ScreenScreenshots saved as Screenshot.png in Documents\VIPRecovery before sendingSplunk
LocationHost name, IP address, country and coordinates from public IP check servicesSplunk; Seqrite

What this can cost you

Seeing the name costs nothing. The risks below apply to a Windows PC where a script from this host ran and the stealer started.

  • High

    Your accounts

    Saved passwords and live session cookies let someone sign in as you, sometimes without needing the password again. Email is the most dangerous loss, because it resets everything else.

  • High

    Money and crypto

    Saved cards can be used online. Splunk describes the clipboard swap: you paste a wallet address and the stealer has quietly put its own there. Crypto sent that way cannot be reversed.

  • High

    Work mail

    These campaigns target businesses with order and invoice lures. Stolen Outlook logins are used for invoice fraud against your customers and suppliers.

  • Medium

    Your home or office network

    Wi-Fi passwords leave the building with the rest of the data. Anyone near your premises could then join the network.

  • Medium

    Discord and Telegram

    Tokens and session data let someone post as you and send the same lure to your contacts.

  • Low

    Nothing, if you only saw the name

    A name in a block list, a log or a warning is not an infection.

What you may notice, and what you may not

A stealer is built to finish its work before anyone notices. Most people learn of it from their accounts, not from the PC.

SignWhat the reports show
Browsers closed by themselvesSplunk says the stealer kills running browser processes before it reads their files. A browser that suddenly closed after you opened an attachment is a strong hint
A folder called VIPRecovery in DocumentsSplunk found screenshots saved there before sending. It may be gone if the stealer cleaned up
A pasted wallet address that does not matchThe clipboard swap changes what you paste. Compare the first and last characters every time
aspnet_compiler.exe or dxdiag.exe running for no reasonBoth are real Windows programs. One running with network use while you did nothing related is worth a look
A logon script in the registryThe value UserInitMprLogonScript under HKEY_CURRENT_USER\Environment holds a path to a script. Most home PCs have no such value
Account alertsSign in from a new place, password reset emails, Discord or Telegram messages you did not send
Nothing at allThe stealer may delete itself after sending. A clean looking PC does not mean nothing was taken

How to check the PC for cablewireltd.site (VIP Keylogger, PowerShell stages)

How a person ends up fetching files from this host

Nobody types cablewireltd.site into a browser. The request comes from a script. We do not know which email or download pointed to this host; the routes below are the ones the researchers found for VIP Keylogger.

  1. 1

    A business email with an attachment

    Splunk lists bank payment notifications, procurement orders and logistics updates as the lures. The attachment is a script file, sometimes inside an archive, with a name that reads like a document.

  2. 2

    An Office or RTF document

    Seqrite describes an email from a supposed buyer with an RTF file named as an order inquiry. Opening it made the PC download a VBScript, which led to PowerShell and a picture hiding the loader.

  3. 3

    Cracked software

    Seqrite's conclusion adds software cracks as a route. A crack that runs a script in the background can start the same chain.

Check your PC before you delete anything

Start with one question: did you open an unexpected attachment, a .js, .vbs or .bat file, or a cracked program around 23 and 24 September 2026, or did a log show a device asking for cablewireltd.site? If yes or not sure, do the checks below. None of them deletes anything.

While you check, do not use the PC for email, banking, work or crypto. A stealer may already have taken what it wanted, but a logon script can run it again at the next sign in.

  1. 1

    Disconnect first

    Turn off Wi-Fi or unplug the network cable on the PC in question. The stealer needs the connection to send data.

  2. 2

    Find which device asked for the address

    If you came from a router page, a DNS log or a security alert, note the device and the time. Only that device is in question.

  3. 3

    Look for the logon script value

    Press Windows key + R, type regedit and open HKEY_CURRENT_USER\Environment. Look for a value named UserInitMprLogonScript and for any unusually long value such as INTERNAL_DB_CACHE. Splunk names both. Write down what the logon script points to; do not delete yet.

  4. 4

    Look in the user folders

    Open %appdata%\Microsoft\Windows\Libraries in File Explorer and look for script files that are not library files. Splunk found the .bat path dropping a hidden file there. Also look in Documents for a VIPRecovery folder.

  5. 5

    Check Startup apps and Task Scheduler

    In Settings > Apps > Startup look for names you did not install. Then press Start, type Task Scheduler and look in Task Scheduler Library for tasks that run PowerShell, wscript or a script from a user folder. Seqrite's loader had options for a startup task and a startup registry entry.

  6. 6

    Look at running programs

    Open Task Manager and look for aspnet_compiler.exe or dxdiag.exe running when you did not start them. Right click and choose Open file location to see where they run from. Their presence alone proves nothing.

  7. 7

    Open Protection history

    In Windows Security > Virus & threat protection > Protection history, look for anything found or blocked around the time you opened the file, especially names with VIPKeylogger, Snake or PowerShell in them.

  8. 8

    Check your accounts from another device

    Look at the recent sign in activity of your email, bank, work, Discord and Telegram accounts. This tells you faster than any file check whether data was used.

How to remove cablewireltd.site (VIP Keylogger, PowerShell stages)

How to remove cablewireltd.site

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to cablewireltd.site or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever cablewireltd.site installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

Scan from outside Windows with Microsoft Defender Offline

Microsoft Defender Offline starts from a trusted environment outside the normal Windows, so malware running inside Windows cannot hide from it as easily. It is built into Windows 10 version 1607 and later and into Windows 11 on x64 PCs.

  1. 1

    Prepare

    Save your work and close programs. Microsoft says the scan takes about 15 minutes and restarts the PC. You need a local administrator account, and the Windows Recovery Environment must be on: in an administrator Command Prompt, reagentc /info shows the state and reagentc /enable switches it on. With it off, Microsoft says, nothing happens and no error shows.

  2. 2

    Suspend BitLocker if it is on

    Microsoft warns that with BitLocker on the system drive, the restart into the scan may ask for the recovery key. Suspend protection first, or have the key ready.

  3. 3

    Start the scan

    Open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. Confirm the prompts. Windows signs you out, scans and boots back normally. In an administrator PowerShell window, Start-MpWDOScan does the same.

  4. 4

    Read the result

    After the restart open Windows Security > Virus & threat protection > Protection history. Microsoft notes the offline scan is not available on ARM versions of Windows and only updates when Microsoft Defender Antivirus is your main antivirus.

  5. 5

    A clean scan is not the end

    A stealer may have run once, sent its data and deleted itself. No scan can undo that. The account steps below matter more than the scan result.

If you use a Mac, an iPhone or an Android phone

The files on cablewireltd.site are PowerShell and Windows script stages, and VIP Keylogger is a .NET program for Windows. Nothing we read says it affects other systems.

Your deviceWhat we knowWhat to do
MacA .ps1 or .js file opened on a Mac does not start this chain; every loader in the reports uses Windows toolsNothing to remove for this threat. Do not follow the Windows steps on a Mac
iPhone or iPadNo source describes VIP Keylogger on iOSNothing to remove. Change passwords that were saved on an infected Windows PC
AndroidNo source mentions itNothing to remove for this threat. Sign out sessions that were open on the Windows PC

After removal: passwords, accounts and prevention

After the PC: protect what was taken

With a stealer, the accounts are the real damage. Do these steps from a phone or another clean computer, in this order, before you trust the PC again.

Five numbered steps: disconnect the PC, change passwords from another device, check the UserInitMprLogonScript value, run an offline scan, reset Windows if unsure
The order of actions if a script from cablewireltd.site ran. Based on Microsoft's pages and Splunk's analysis; not tested on an infected PC.
  1. 1

    Change email passwords first

    Your email account resets every other account, so it comes first. Use a new password you have never used before, then change bank, work, cloud storage and shop accounts.

  2. 2

    Sign out every session

    Stolen cookies keep a login alive even after a password change. In each important account, use the option to sign out of all devices or end other sessions. In Discord, change the password, which also resets the token.

  3. 3

    Turn on two step sign in

    Use an authenticator app or a security key wherever it is offered, so a password alone is not enough next time.

  4. 4

    Call your bank about saved cards

    If cards were saved in a browser on the PC, ask the bank to block and reissue them. Watch statements for a few weeks.

  5. 5

    Move crypto to a new wallet

    If a wallet or seed phrase was on the PC, create a new wallet on a clean device and move the funds. Check recent transfers for a swapped address.

  6. 6

    Change the Wi-Fi password

    Splunk describes the stealer reading saved Wi-Fi passwords. Change the router's Wi-Fi password and reconnect your devices.

  7. 7

    If unsure, reset Windows

    Microsoft's recovery options include Reset this PC, reached in Windows 11 from Settings > System > Recovery and from Troubleshoot > Reset this PC in the recovery environment. Keep my files removes apps and settings; for a PC that ran a stealer, Remove everything is the choice that does not depend on finding every piece. Back up documents first; Microsoft calls the reset its most disruptive option.

  8. 8

    Restore only documents

    Copy back documents and photos by hand, not programs or scripts. Install programs again from their makers' own sites.

  9. 9

    Warn the people you work with

    If work mail was on the PC, tell your colleagues and regular customers. Stolen mailboxes are used to send fake invoices that look real.

Keep a PC out of this kind of chain

Every VIP Keylogger chain the researchers describe needs one action from a person: opening a file. That is where it is easiest to stop.

Do

  • Show file name extensions in File Explorer (View > Show > File name extensions in Windows 11) so an invoice.pdf.js is visible for what it is.
  • Treat an order, payment notice or shipping update with an attachment you did not expect as an attack until you confirm it by phone.
  • Keep Windows and Microsoft Defender updated.
  • Use a password manager instead of saving passwords in the browser.
  • Turn on two step sign in for email, bank and work accounts.
  • Keep a backup of documents on a drive you unplug.

Don't

  • Do not double click .js, .vbs, .bat or .ps1 files that arrive by email or in a download.
  • Do not run cracked programs or key generators.
  • Do not change your passwords on the PC you suspect.
  • Do not paste a wallet address without checking it afterwards.
  • Do not take a quiet scan as proof that nothing was taken.

Questions about cablewireltd.site (VIP Keylogger, PowerShell stages)

What is cablewireltd.site?

It is a web address that URLhaus, the malware tracking project of abuse.ch, lists for nine malware files reported on 23 and 24 September 2026: seven PowerShell scripts named Crypted.ps1 and two JavaScript files.

Three are tagged VIPKeylogger. The domain was registered on 21 September 2026 and is now on server hold. It is not a program on your PC and not a site anyone is meant to visit.

Is cablewireltd.site safe?

No. It served malware files, and the fact that it is offline now does not change that. Our server could not resolve the name on 10 October 2026, and RDAP shows the status server hold, which usually follows an abuse report. Do not run any script that refers to it, and do not try to reach it.

What is Crypted.ps1?

It is the name used for seven PowerShell scripts on this host. PowerShell is a scripting tool built into Windows.

A file like this is a middle stage of an infection: a script the victim opened downloads it, and it then fetches and starts the next part. We did not open these files, so the exact content is not confirmed by us.

What is VIP Keylogger?

It is a .NET stealer for Windows that Seqrite describes as similar to Snake Keylogger. Splunk studied more than 200 of its loaders in 2026. It records keystrokes and takes saved browser passwords, cookies, cards and autofill data, email and Discord logins, Wi-Fi passwords, clipboard text and screenshots, then sends them to a Telegram bot or a server.

I saw cablewireltd.site in my firewall or DNS log. Am I infected?

Not necessarily. The name alone proves nothing. It does mean a device on your network asked for it, and people do not usually do that by hand.

Find the device, disconnect it, and do the checks on this page:

  • the UserInitMprLogonScript value
  • startup entries
  • Protection history
  • a Microsoft Defender Offline scan

Change passwords from another device.

How do I remove VIP Keylogger from Windows?

First change passwords and sign out sessions from another device. Then check HKEY_CURRENT_USER\Environment for a UserInitMprLogonScript value, look at Startup apps and Task Scheduler, and run Microsoft Defender Offline from Windows Security, Virus and threat protection, Scan options. If you are not sure the PC is clean, use Reset this PC with Remove everything and restore only documents.

My browser closed by itself after I opened an attachment. Is that a sign?

It can be. Splunk reports that VIP Keylogger kills running browser processes before it reads their password and cookie files. A browser closing right after you opened an unexpected attachment is a strong reason to disconnect the PC and follow the steps on this page.

On its own, a browser closing is common and proves nothing; together with an unexpected script file it is worth acting on.

Does cablewireltd.site affect Mac, iPhone or Android?

We found nothing that says so. The files are PowerShell and Windows script stages and VIP Keylogger is a Windows .NET program.

On a Mac, iPhone or Android there is nothing to remove for this threat. Change any password that was saved on an infected Windows PC, from whichever device you trust.

Will resetting Windows protect my accounts?

No. A reset removes the stealer and its logon script from the PC, but it cannot bring back what was already sent. Saved passwords, cookies and cards stay in the attackers' hands until you change the passwords, sign out all sessions, block the cards and turn on two step sign in, from a clean device.

Will Fortect remove cablewireltd.site?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For cablewireltd.site, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove AIGPUSniffer: what it is, is it a virus, and how to remove it

AIGPUSniffer.exe is a small Adobe helper that Illustrator and InDesign start for a second or two to test your graphics card before they turn on GPU acceleration. It is not a virus and not part of ASUS software: you...FLMedium riskUgnius Kiguolis ·

Remove TrojanDownloader:PowerShell/Falsip.A

TrojanDownloader:PowerShell/Falsip.A is designed to download malware on your computer TrojanDownloader:PowerShell/Falsip.A is a detection of a Trojan Horse by Microsoft Windows Defender. Programs with Trojan-like features are capable of multipleTrojansHigh riskAlice Woods ·

Remove Fake Adobe Flash Player install

Fake Adobe Flash Player install spreads malicious programs Fake Adobe Flash Player install or update pop-up might show up on the screen out of nowhere. While Flash Player is aTrojansHigh riskGabriel E. Hall ·

Remove "The Requested Resource is in Use" error

"The Requested Resource is in Use" error - a dangerous Trojan virus that is capable of evading antivirus detection "The Requested Resource is in Use" error is a sign ofTrojansHigh riskLucia Danes ·

Questions and experiences: cablewireltd.site (VIP Keylogger, PowerShell stages)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,451 members already hereReading, writing, commenting and voting. 0 verified · 176 joined this year