Threat Advisory

New PowerShell Keylogger Covertly Captures Sensitive Information

Threat: Malware
Targeted Region: Global
Threat Actor Region: French
Targeted Sector: Technology & IT, Finance & Banking
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have identified keylogger, operating through a PowerShell script, poses significant risks to both organizations and individuals by stealthily capturing sensitive information. Keyloggers are among the most dangerous types of malwares, capable of monitoring every keystroke on an infected system. This analysis highlights the alarming capabilities of this keylogger, which is designed to infiltrate systems, collect sensitive data, and communicate with attackers in an anonymized manner.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have identified keylogger, operating through a PowerShell script, poses significant risks to both organizations and individuals by stealthily capturing sensitive information. Keyloggers are among the most dangerous types of malwares, capable of monitoring every keystroke on an infected system. This analysis highlights the alarming capabilities of this keylogger, which is designed to infiltrate systems, collect sensitive data, and communicate with attackers in an anonymized manner.[emaillocker id="1283"]

This keylogger operates through a PowerShell script that employs several advanced techniques for execution and data exfiltration. It uses the Command and Scripting Interpreter to run commands without user interaction, indicating automated malicious activity. The script conducts comprehensive system discovery, gathering vital information such as user profile directories and cryptographic settings. Communication with the command-and-control (C2) server is facilitated through a cloud server in Finland and an Onion server on the Tor network, ensuring anonymity. The script also incorporates functionality for screen capture, Base64 encoding for secure command transmission, and persistent connection attempts via a SOCKS proxy. Notably, comments within the script suggest the developer is likely a French speaker, which could provide insight into the attacker's origin.

The emergence of this PowerShell keylogger underscores the critical need for enhanced security measures to combat malware threats. Its ability to covertly capture sensitive information and communicate through anonymized channels poses a serious risk to affected systems. Organizations are advised to implement vigilant monitoring strategies and robust protocols to mitigate the impact of such advanced threats. As the landscape of cyber threats continues to evolve, awareness and preparedness remain paramount.

THREAT PROFILE:

Tactic Technique Id Technique
 Execution T1059 Command and Scripting Interpreter
Discovery  T1082 System Information Discovery
 T1083 File and Directory Discovery
Command and Control  T1571 Non-Standard Port

REFERENCES:

The following reports contain further technical details:
https://www.cyfirma.com/research/cyfirma-research-powershell-keylogger/

[/emaillocker]
crossmenu