Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » North Korean hackers deploy new KLogEXE and FPSpy malware in targeted attacks
Global Security

North Korean hackers deploy new KLogEXE and FPSpy malware in targeted attacks

AdminBy AdminSeptember 26, 2024No Comments2 Mins Read
KLogEXE and FPSpy Malware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


September 26, 2024Ravi LakshmananCyber ​​attack / malware

KLogEXE and FPSpy malware

Attackers linked to North Korea have been seen using two new varieties of malware, dubbed KLogEXE and FPSpy.

The activity was attributed to an adversary tracked as Kimsukiwhich is also known as APT43, ARCHIPELAGO, Black Banshee, Emerald Sleet (formerly Thallium), Sparkling Pisces, Springtail and Velvet Chollima.

“These samples expand Sparkling Pisces’ already extensive arsenal and demonstrate the group’s continued evolution and increasing capabilities,” Palo Alto Networks Division 42 researchers Daniel Frank and Lior Rochberger said.

Cyber ​​security

Active since at least 2012, the threat has been dubbed the “king of phishing” for its ability to trick victims into downloading malware sending emails which gives the impression that they are from reliable parties.

Unit 42’s analysis of the Sparkling Pisces infrastructure revealed two new portable executables called KLogEXE and FPSpy.

KLogExe is a C++ version of a PowerShell-based keylogger called InfoKey that was highlighted JPCERT/CC in connection with Kimsuky campaign targeting Japanese organizations.

KLogEXE and FPSpy malware

The malware is equipped with capabilities to collect and steal information about the programs currently running on the compromised workstation, keystrokes and mouse clicks.

On the other hand, FPSpy is considered a backdoor variant of AhnLab opened in 2022, with overlaps identified with malware that Cyberseason documented as KGH_SPY at the end of 2020.

Cyber ​​security

FPSpy, in addition to keylogging, is also designed to collect system information, download and execute additional payloads, execute arbitrary commands, and list drives, folders, and files on an infected device.

Unit 42 said it was also able to detect points of similarity in the source code of KLogExe and FPSpy, suggesting that they are likely the work of the same author.

“Most of the targets we observed during our study originated from South Korea and Japan, which is consistent with previous targeting of Kimsuki,” the researchers said.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.