NidLog is a PowerShell keylogger associated with Kimsuky/APT43 activity. Breakglass reporting cited in the provided content states that researchers dumped a live Kimsuky command-and-control server and recovered the full kill chain, including a CHM dropper, a VBScript stager, and the NidLog PowerShell keylogger. The activity is linked to Kimsuky infrastructure hosted on Vultr Seoul VPS nodes and used in credential-harvesting and phishing campaigns targeting South Korean entities and users, especially Naver accounts, the Korean National Tax Service/HomeTax platform, and Korean government portals. The broader infrastructure cluster used dynamic DNS providers including mydns, dynv6, dns.army, dns.navy, and kro.kr, and included domains such as mdlog[.]mydns[.]vc identified as associated with logging or exfiltration. Related infrastructure mentioned in the content includes 158.247.219[.]150 and 158.247.250[.]37, with the cluster assessed with high confidence as consistent with Kimsuky/APT43 operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Over the past several weeks, we have documented a pattern of Vultr Seoul VPS abuse by actors consistent with the Kimsuky cluster — from the 740-hostname phishing factory on 158.247.219.150, to the CHM/NidLog C2 payload recovery...
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
NidLog is referenced as a recovered C2 payload associated with Kimsuky infrastructure. In this content it appears tied to phishing infrastructure and logging/exfiltration activity, suggesting use for credential capture or data collection.
PowerShell-based keylogger referenced in the recovered Kimsuky kill chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.