BRUSHLOGGER is a 32-bit Windows keylogger observed alongside the BRUSHWORM modular backdoor in an intrusion targeting a financial institution in South Asia. It is deployed through DLL side-loading while masquerading as a legitimate Windows library. The malware executes during DLL initialization, uses a low-level Windows keyboard hook to capture system-wide keystrokes, and records foreground-window titles and timestamps to contextualize captured input. It stores collected keystroke data in locally XOR-obfuscated logs. BRUSHLOGGER can collect credentials, financial information, and sensitive internal communications entered on an infected system.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
BRUSHWORM stores configuration fields encrypted with AES-CBC; BRUSHLOGGER XOR-encrypts keystroke logs using byte 0x43.
BRUSHWORM, disguised as paint.exe... BRUSHLOGGER, meanwhile, masqueraded as libcurl.dll, a commonly trusted Windows library... using socially engineered filenames like Salary Slips.exe, Documents.exe, and Dont Delete.exe
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A keylogger delivered as a separate binary and disguised as libcurl.dll via DLL side-loading. It records keystrokes and active window titles to harvest credentials, financial inputs, and internal communications.
A 32-bit Windows DLL keylogger designed for DLL side-loading while masquerading as libcurl.dll. It uses a low-level WH_KEYBOARD_LL hook to capture system-wide keystrokes and foreground-window context, then saves logs under ProgramData using a username-derived MD5 filename. Log data is XOR-obfuscated with byte 0x43.
Custom keylogger delivered as a DLL side-loading component masquerading as libcurl.dll. It installs a system-wide low-level keyboard hook, records keystrokes with active window context and timestamps, and stores XOR-encrypted logs on disk. It uses a mutex for single-instance execution and exports fake curl_easy_* functions as stubs.
A custom DLL-side-loaded keylogger observed targeting a South Asian financial institution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.