KMLOG is a custom Windows keylogger used by the Earth Kurma cyberespionage group against government and telecommunications organizations in Southeast Asia. It records victim keystrokes to harvest credentials and stores the collected logs in files disguised as ZIP archives. Earth Kurma deployed KMLOG during post-compromise activity alongside tooling for reconnaissance, lateral movement, stealthy persistence, and document exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
1 distinct technique documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Keylogger that captures keystrokes and stores them in disguised ZIP files for later exfiltration.
Custom keylogger that captures keystrokes and stores logs disguised as ZIP files to reduce suspicion and aid credential theft.
Keylogger used to harvest credentials from compromised environments.
KMLOG is a custom keylogger used to steal credentials by logging keystrokes to a hidden file, obfuscated with a fake ZIP header.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.