PSLogger
Description
The keylogging routine uses the GetKeyState and GetAsyncKeyState APIs and is not sophisticated, and logged keystroke and clipboard context is saved in plaintext.
The malware’s other functionality is to capture the desktop, compressing the images and saving them in the same directory.
Names
Name |
---|
PSLogger |
ECCENTRICBANDWAGON |
Category
Malware
Type
- Reconnaissance
- Backdoor
- Keylogger
- Credential stealer
- Info stealer
Information
- https://norfolkinfosec.com/a-lazarus-keylogger-pslogger/
- https://us-cert.cisa.gov/ncas/analysis-reports/ar20-239a
Malpedia
Other Information
Uuid
2744d3b4-396f-45ab-8d05-a2d08082c97f
Last Card Change
2022-12-29