#KEYLIME
Malware/Tool
2018-10-03 • APT38 Un-usual Suspects
KEYLIME is a keylogger used by APT38 during financially motivated intrusions. In early 2014, the group deployed KEYLIME with the NESTEGG backdoor against systems specific to a Southeast Asian financial institution. The activity preceded APT38’s later focus on SWIFT environments and was assessed as part of the group’s effort to learn systems involved in financial transactions. In APT38’s operational lifecycle, KEYLIME appears in the foothold stage before privilege escalation, internal reconnaissance, and completion of the financial mission.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days