216.73.216.6

Recent Keylogger Attributed to North Korean Group Andariel

· Published 04/11/2024 17:12 · Modified 04/11/2024 21:32

Export JSON

Essential information

Published
04/11/2024 17:12
Modified
04/11/2024 21:32
Tags
2024-11-04 andariel keylogger anti-analysis apt45 clipboard theft hook procedures keylogger persistence
Related entities
1 observables, 1 intrusion sets (apt), 14 techniques (mitre), 1 malware, 1 others

Description

A new , attributed to the North Korean group Andariel (), has been linked to targeted attacks against U.S. organizations. The malware captures keystrokes and mouse activity, storing data in an encrypted archive. It employs techniques like code obfuscation through junk code. The sets global Windows hooks to intercept keystrokes and mouse events, modifies registry for , and creates a password-protected archive in the temp folder. It uses SetWindowsHookEx API for keyboard and mouse event monitoring, and GetMessageW API for message queue handling. The malware also steals clipboard data and logs special key presses. Hybrid Analysis effectively identified the 's capabilities, mechanism, and log file creation, providing valuable insights for threat analysis.

External references