KiloAlfa is a Lazarus Group malware implant associated with North Korean state-sponsored intrusion activity. It is documented as containing keylogging functionality and as collecting application window titles, indicating use for user activity monitoring and credential-focused surveillance during post-compromise operations. KiloAlfa has also been used to obtain user tokens from interactive sessions and relaunch itself in the context of the logged-in user via CreateProcessAsUserA, reflecting tradecraft aimed at operating under a victim user context and improving access to user-session resources.
KiloAlfa is part of the broader Lazarus malware ecosystem used in espionage, financially motivated operations, and destructive campaigns against enterprises and other organizations. Lazarus has targeted sectors including banking, defense, software, pharmaceuticals, manufacturing, electrical industries, and cryptocurrency-related organizations across multiple countries. Within that ecosystem, KiloAlfa appears to function as a surveillance and post-exploitation component rather than a standalone destructive payload, supporting collection of sensitive user input and contextual information from compromised Windows systems.
Lazarus operations associated with tools such as KiloAlfa commonly rely on spearphishing, malicious documents, and social-engineering lures for initial access, followed by extensive credential theft, lateral movement, persistence, and data exfiltration. KiloAlfa’s observed behavior aligns with that broader operational model by enabling keystroke capture and execution under an interactive user context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lazarus Group malware KiloAlfa contains keylogging functionality.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus-associated malware family listed as related malware.
Malware containing keylogging functionality.
A Lazarus Group keylogger with token theft and process creation capabilities; it also reports foreground window titles and contains keylogging functionality.
Malware containing keylogging functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.