216.73.216.233

PowerShell Keylogger

· Published 04/09/2024 09:05 · Modified 04/09/2024 09:45

Export JSON

Essential information

Published
04/09/2024 09:05
Modified
04/09/2024 09:45
Tags
2024-09-04 keylogger powershell proxy screen capture
Related entities
3 observables, 5 techniques (mitre), 1 others

Description

A newly identified operating via script has been analyzed, revealing its capabilities to capture keystrokes, gather system information, and exfiltrate data. The malware uses a cloud server in Finland as a and an Onion server for C2 communication, ensuring anonymity. It implements various functions including , encoded command execution, and persistent connection attempts. The 's code suggests a French-speaking developer. While sophisticated in its approach, the persistence mechanism remains incomplete, indicating potential future enhancements. The analysis highlights the need for robust security measures against such stealthy threats.

External references