KeyBase is a commercial Windows credential-stealing malware family first observed in 2015 and widely used in phishing-led intrusion activity. Although commonly described as a keylogger, it is more accurately a full credential-theft suite that steals passwords from web browsers and email clients, records keystrokes, captures clipboard contents, and can take periodic screenshots, including application-triggered captures through an InstaLogging feature. It also supports additional operator functions such as download-and-execute, configurable kill timers or self-destruct dates, and persistence on infected hosts.
KeyBase is implemented in C# on the .NET Framework and uses simple obfuscation and encrypted strings to hinder analysis. Multiple analyses have documented its use of embedded Nirsoft password-recovery utilities, extracted at runtime, to harvest stored credentials. Stolen data is uploaded over HTTP to a web-based management panel known as Keypanel, which allows operators to review infected systems, screenshots, clipboard captures, passwords, and keystroke logs. Historical investigations also identified serious operational security weaknesses in some KeyBase panel deployments, including exposed screenshot repositories and insecure upload handling.
Distribution has been strongly associated with phishing campaigns using business-themed lures such as purchase orders, quotations, invoices, shipping documents, and payment-related messages. Campaigns have also used archived executables and, in some cases, Office exploit kits. Victimology has included organizations across manufacturing, transportation and logistics, wholesale and retail, engineering, hospitality, healthcare, education, and high technology, with notable concentrations in Asia, the Middle East, and other globally distributed regions. Observed activity indicates both broad opportunistic targeting and role-focused targeting of personnel such as sales staff, purchasing teams, admissions staff, and hotel receptionists.
KeyBase has been used by a wide range of financially motivated actors, including operators involved in business email compromise ecosystems such as SilverTerrier. It has also appeared in multistage malware chains alongside other stealers. The malware’s combination of credential theft, keylogging, screenshot capture, and simple web-panel management made it a low-cost but effective tool for account compromise, invoice and supply-chain fraud, and broader information theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Unit 42 identified ten strains of info-stealers popular with SilverTerrier: AgentTesla, Atmos, AzoRult, ISpySoftware, ISR Stealer, KeyBase, LokiBot, Pony, PredatorPain, and Zeus.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
the final infection on September 13 showed that the e-mail... was sourced from an internal e-mail address of the company... Then they login to a compromised company e-mail account and appear to be adding e-mails from their contact list
The author makes use of a number of simple obfuscation techniques on various strings used within the code. Examples of this include replacing single characters that have been added to strings, as well as performing reverse operations on strings.
KeyBase is more than just a simple keylogger, it is a complete credential stealing suite. Aside from stealing credentials from all popular web browsers and email clients, KeyBase is also capable of storing keystrokes...
Information stealers seem to be the preferred type of malware to help in their fraudulent email attacks... The attacker can pilfer data about the targets and use it to create efficient messages for diverting transactions or asking money to be sent to fraudsters' account.
KeyBase is more than just a simple keylogger, it is a complete credential stealing suite. Aside from stealing credentials from all popular web browsers and email clients, KeyBase is also capable of storing keystrokes...
68 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a family with code overlap to PhantomStealer according to vendor analysis, not as the primary malware under investigation.
Mentioned as another malware/tool appearing in execution chains together with BloodyStealer.
Information stealer used by SilverTerrier actors in support of business email compromise fraud.
Commercial credential-stealing malware with a server-side management panel. It steals passwords from browsers and email clients, logs keystrokes, captures clipboard data, can take screenshots, persists via the Startup folder, and exfiltrates data through web uploads to a PHP-based control panel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.