#PSLogger

Malware/Tool

2019-01-22 • A Lazarus Keylogger- PSLogger

PSLogger is a Windows keylogging and screen-capture utility connected to attempted intrusions against financial organizations in Vietnam and activity attributed to North Korean adversaries interested in the financial sector. One version is a DLL injected through a modified PowerSploit framework; another is a standalone executable submitted from Pakistan and possibly used in a regional intrusion. Its Syschk.ps1 loader contains a Base64-encoded DLL, a Base64-encoded Invoke-ReflectivePEInjection variant, and routines that decode and execute both components.

Tagged Reports

« Back