MECHANICAL is a PowerShell-based keylogger associated with the North Korea-linked threat actor Kimsuky. The provided content states that Kimsuky has used MECHANICAL to log keystrokes on victim systems, and one source additionally describes it as a cryptojacker. The malware is referenced in the context of Kimsuky operations that target individuals, think tanks, and government-related entities, particularly in South Korea, Japan, and the United States, in support of intelligence collection. High-confidence details in the content are limited to its use for keystroke logging and its association with Kimsuky; no specific infection vector, command-and-control details, or indicators of compromise for MECHANICAL itself are provided in the supplied material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes.
1 distinct technique documented for this family, organized by ATT&CK tactic.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used for logging keystrokes.
Keylogging tool used to capture victim keystrokes for credential theft and intelligence collection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.