KEYLIME is a trojan associated with APT38, the financially motivated subgroup of the Lazarus Group linked to North Korea. It has been used in post-compromise collection activity on Windows systems, with documented capabilities including keystroke logging and clipboard data theft. These functions enable the collection of user input and copied data that may contain credentials, financial information, or other sensitive material. KEYLIME appears in reporting on Lazarus and BlueNorOff tooling as part of a broader ecosystem of malware used to support espionage and financially motivated intrusions, particularly against organizations of interest to North Korean operators. Based on available information, KEYLIME is best characterized as a credential- and information-collecting trojan used during victim monitoring and data collection phases of an intrusion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT38 used a Trojan called KEYLIME to capture keystrokes from the victim’s machine.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family associated with BlueNorOff operations.
Trojan used to capture keystrokes.
A trojan used to collect data from the clipboard.
Trojan used to collect clipboard data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.