A Lazarus Keylogger- PSLogger

2019-01-22 Norfolk

https://norfolkinfosec.com/a-lazarus-keylogger-pslogger/

Thumbnail for A Lazarus Keylogger- PSLogger

The source analyzes PSLogger, a keylogging and screen-grabbing utility connected to attempted intrusions against financial organizations in Vietnam. Two observed versions include a DLL injected through a modified PowerSploit framework and a standalone executable submitted from Pakistan. The tool's collection capabilities and contextual links place it within financially focused activity commonly associated with North Korean adversaries.

Indicators of Compromise

Type Value First Seen Last Seen
HASH efd470cfa90b918e5d558e5c8c38213… 2019-01-22 2020-08-26
HASH c6930e298bba86c01d0fe2c8262c46b… 2019-01-13 2020-08-26
HASH 791205487bae0ac814440573e992ba2… 2019-01-13 2019-01-22
HASH ed7fcb9023d63cd9367a3a455ec9433… 2018-07-23 2019-01-22
HASH 26466867557f84dd4784845280da1f27 2018-07-23 2019-01-22

Related Actors

Related Reports

« Back