Recent Keylogger Attributed to North Korean Group Andariel Analyzed Through A Hybrid Analysis Perspective

2024-11-04 Hybrid Analysis

https://hybrid-analysis.blogspot.com/2024/11/recent-keylogger-attributed-to-north.html

Thumbnail for Recent Keylogger Attributed to North Korean Group Andariel Analyzed Through A Hybrid Analysis Perspective

Andariel, also tracked as APT45, Silent Chollima, and Onyx Sleet, is linked in the source to a recently disclosed keylogger used against U.S. organizations. The malware installs low level keyboard and mouse hooks with SetWindowsHookExW, persists by modifying the Windows Run registry key, and hides execution flow with junk code and an encrypted payload that is decrypted in memory. It writes captured activity to a password protected archive named DT_0004.tmp in %TEMP%, which extracts a04.log. The Hybrid Analysis view shows credential theft risk and anti-analysis tradecraft useful for detecting the sample.

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back