Threats Tagged 'keylogging'
View all threats tagged with 'keylogging'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'keylogging'
Click on any threat for detailed analysis and mitigation recommendations
This analysis examines the evolution of Remcos, a Remote Access Trojan that has become a significant global threat. Originally a commercial tool, Remcos now provides attackers with capabilities such as credential theft, keylogging, screen capture, and webcam control. The latest variant exhibits real-time command-and-control communication, enabling immediate surveillance. The malware uses sophisticated techniques like dynamic API resolution, encrypted configurations, and modular plugins to evade detection. It establishes persistence through registry modifications and employs cleanup routines to remove traces of its activity. The report details Remcos' infection vectors, data exfiltration methods, and its network interactions with command-and-control servers. Join the discussion | AlienVault OTX General | 02/18/2026, 16:50:28 UTC Added: 02/18/2026, 19:26:13 UTC |
An exposed open directory on a command and control server revealed a complete deployment of the BYOB (Build Your Own Botnet) framework. The multi-stage infection chain targets Windows, Linux, and macOS platforms, implementing seven persistence mechanisms. The malware includes extensive post-exploitation capabilities such as keylogging, packet capture, and email harvesting. Analysis uncovered a modular design with encrypted C2 communications and infrastructure reuse across multiple regions. Two nodes also hosted XMRig cryptocurrency miners, indicating additional monetization efforts. The campaign has been operational for approximately 10 months, demonstrating geographic and provider diversification in its infrastructure. Join the discussion | AlienVault OTX General | 01/29/2026, 12:49:58 UTC Added: 01/29/2026, 16:27:48 UTC |
A new campaign by Kimsuky involves distributing malicious mobile apps through QR codes and phishing websites. The apps, masquerading as delivery services, VPNs, and cryptocurrency tools, decrypt an embedded APK to deploy a RAT with extensive capabilities. The malware uses a native decryption function and diverse decoy behaviors. Infrastructure overlaps and Korean language comments link this activity to Kimsuky. The threat actor employs sophisticated phishing techniques and leverages QR codes to redirect victims to malicious downloads. The malware requests extensive permissions and implements keylogging, audio recording, and data exfiltration. Multiple C&C servers were identified, some hosting Naver and Kakao phishing sites. Join the discussion | AlienVault OTX General | 12/16/2025, 14:57:28 UTC Added: 12/16/2025, 19:16:51 UTC |
This analysis examines the latest attack flow of the KimJongRAT variant, attributed to the North Korean threat actor Kimsuky. The malware has evolved to include both PE-based and PowerShell-based attack chains, which have been merged into a single workflow. The attackers use phishing emails for initial access, leveraging GitHub and Google Drive for malware distribution. The malware exfiltrates sensitive data including browser credentials, system information, and keystrokes. Additional activities by the same actor include credential theft through phishing sites and spear-phishing campaigns targeting South Korean users. The analysis provides evidence supporting the attribution to Kimsuky and highlights the ongoing development of variants and infrastructure, indicating successful attacks. Join the discussion | AlienVault OTX General | 11/24/2025, 11:59:25 UTC Added: 11/24/2025, 12:22:41 UTC |
Sturnus is a newly identified Android banking trojan targeting financial institutions in Southern and Central Europe. It features advanced capabilities such as full device takeover, harvesting banking credentials, keylogging, and remote control via VNC. Notably, it can bypass encryption on popular messaging apps like WhatsApp, Telegram, and Signal to monitor communications. The malware uses sophisticated communication protocols including WebSocket and HTTP to interact with its command-and-control servers. Although still in development and not yet exploited in the wild, Sturnus poses a significant threat to financial security and user privacy. It employs HTML overlays for data exfiltration and extensive environment monitoring to evade detection. The malware’s complexity and targeting of Android devices make it a serious concern for European financial sectors. Defenders should prioritize detection and containment measures to mitigate potential impacts. Join the discussion | AlienVault OTX General | 11/20/2025, 19:42:43 UTC Added: 11/20/2025, 21:58:50 UTC |
DarkComet RAT malware has resurfaced disguised as a fake Bitcoin-related tool, distributed via a RAR archive containing a UPX-packed executable. Upon execution, it installs itself as 'explorer.exe' in the user's AppData folder and establishes persistence through a registry run key. The malware communicates with its command and control server at kvejo991.ddns.net on port 1604. It performs keylogging, storing captured keystrokes in a dedicated folder, and uses process injection into notepad.exe to evade detection. The malware also spawns multiple cmd.exe and conhost. Join the discussion | AlienVault OTX General | 11/14/2025, 12:09:29 UTC Added: 11/14/2025, 12:31:21 UTC |
A new Astaroth banking trojan campaign has been discovered abusing GitHub to host malware configurations. The infection begins with a phishing email containing a link to download a zipped Windows shortcut file, which installs the Astaroth malware. The trojan detects when users access banking or cryptocurrency websites and steals credentials through keylogging. It sends stolen information to attackers using Ngrok reverse proxy and uses GitHub to update its configuration when command and control servers become inaccessible. The malware primarily targets South American countries, with a focus on Brazil. Astaroth employs various anti-analysis techniques and targets specific banking and cryptocurrency-related sites. The GitHub repositories hosting the malicious configurations have been reported and taken down. Join the discussion | AlienVault OTX General | 10/14/2025, 09:10:41 UTC Added: 10/14/2025, 09:21:37 UTC |
A new botnet called NightshadeC2 has been identified, employing sophisticated techniques to bypass malware analysis sandboxes and exclude itself from Windows Defender. It uses a 'UAC Prompt Bombing' technique and has both C and Python variants. The botnet's capabilities include reverse shell, file execution, self-deletion, remote control, screen capture, hidden web browsers, and keylogging. It's being distributed through ClickFix attacks and trojanized legitimate software. The botnet uses encryption for C2 communication and gathers victim information. It also employs various persistence mechanisms and can bypass certain sandbox environments. The discovery highlights the evolving sophistication of malware and the need for advanced detection and response capabilities. Join the discussion | AlienVault OTX General | 09/05/2025, 10:46:25 UTC Added: 09/05/2025, 14:40:58 UTC |
This report details a cyber-espionage campaign attributed to Kimsuky, a North Korean APT group, targeting South Korean entities. The attack uses malicious Windows shortcut files as initial access, followed by obfuscated scripts and a sophisticated malware framework. The malware performs extensive system profiling, steals credentials and sensitive documents, monitors user activity, and exfiltrates data over standard web traffic. It establishes persistence, evades detection, and maintains communication with command-and-control infrastructure. The campaign demonstrates Kimsuky's evolution in stealth, modularity, and targeting precision, representing a serious espionage threat that requires advanced behavioral monitoring and network anomaly detection to combat. Join the discussion | AlienVault OTX General | 08/07/2025, 11:19:25 UTC Added: 08/07/2025, 15:17:45 UTC |
A sophisticated Android banking trojan named RedHook has been discovered targeting Vietnamese users through spoofed government and financial websites. The malware uses WebSocket to communicate with its command-and-control server and supports over 30 remote commands, enabling complete control over compromised devices. RedHook combines phishing, RAT, and keylogging capabilities to exfiltrate credentials and conduct fraud. It abuses Android's MediaProjection API for screen capture and sends data to a live C2 server. The malware's low antivirus detection rate makes it a stealthy and active threat. Code artifacts suggest development by a Chinese-speaking threat actor or group. An exposed AWS S3 bucket revealed operational data dating back to November 2024, indicating a shift from previous scam campaigns to this advanced banking trojan. Join the discussion | AlienVault OTX General | 07/31/2025, 19:23:46 UTC Added: 07/31/2025, 19:32:44 UTC |
Showing 1 to 10 of 10 results