#KLogEXE

Malware/Tool

2024-09-26 • Unraveling Sparkling Pisces’s Tool Set: KLogEXE and FPSpy

KLogEXE is an undocumented keylogger used by Sparkling Pisces, also known as Kimsuky. Its name is supported by the sample's dialog resource and internal KLogExe designation; the analyzed portable executable was named powershell.exe. Unit 42 discovered it while pivoting through infrastructure connecting PowerShell malware, KLogEXE, and the FPSpy backdoor variant, including similar domains registered with the same email address. The broader actor has repeatedly lured victims into downloading and running malicious payloads, recently impersonating a legitimate Korean company and signing malware with a valid certificate.

Tagged Reports

« Back