A Lazarus Keylogger- PSLogger

2019-01-22 • Norfolk •

https://norfolkinfosec.com/a-lazarus-keylogger-pslogger/

Thumbnail for A Lazarus Keylogger- PSLogger

The source analyzes PSLogger, a keylogging and screen-grabbing utility connected to attempted intrusions against financial organizations in Vietnam. Two observed versions include a DLL injected through a modified PowerSploit framework and a standalone executable submitted from Pakistan. The tool's collection capabilities and contextual links place it within financially focused activity commonly associated with North Korean adversaries.

Indicators of Compromise

Type Value First Seen Last Seen
HASH efd470cfa90b918e5d558e5c8c38213… 2019-01-22 2020-08-26
HASH c6930e298bba86c01d0fe2c8262c46b… 2019-01-13 2020-08-26
HASH 791205487bae0ac814440573e992ba2… 2018-07-23 2019-01-22

Related Actors

Related Reports

« Back