Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another contemporary credential stealer/keylogger for comparison with KeyBase's password-stealing functionality.
A surveillance malware/keylogger family used primarily in cybercrime campaigns to steal authentication data. It captures keystrokes and also supports browser and email credential dumping, screenshot capture, collection of system configuration information, logging of browser and email activity, and exfiltration via email, PHP-based web panel, or FTP.
Commercially available keylogger/infostealer used to capture and exfiltrate sensitive data (e.g., website credentials, financial information, chat sessions, and email contents).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.