Hotkeyz is a Windows proof-of-concept hotkey-based keylogger created by Jonathan Bar Or. It abuses the Windows RegisterHotKey API by registering individual alphanumeric keys and selected additional keys as global hotkeys. It collects resulting WM_HOTKEY messages, extracts virtual-key codes, and records them to a text file. To preserve normal user input behavior, it temporarily unregisters the intercepted hotkey, simulates the original keystroke, and registers the hotkey again. Hotkeyz demonstrates a keylogging approach that does not rely on conventional keyboard hooks, polling, Raw Input, or DirectInput mechanisms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
For instance, the following code snippet demonstrates how to use the RegisterHotKey API to register the A key (with a virtual-key code of 0x41) as a global hotkey... In Hotkeyz, it first registers each alphanumeric virtual-key code ... as individual hotkeys by using the RegisterHotKey API.
ユーザにキーロガーの存在を気取られないため、メッセージからvirtual-key codeを取り出した時点で、いったんそのキーのホットキー登録をUnregisterHotKey APIを使って解除し、その上でkeybd_eventを使ってキーを送信することです。これにより、ユーザからは問題無くキーが入力出来ているように見え、キーが裏で窃取されていることに気が付かれにくくなります。
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A proof-of-concept hotkey-based keylogger for Windows that registers many keys as global hotkeys, captures WM_HOTKEY messages, extracts virtual-key codes, temporarily unregisters the hotkey, simulates the key press with keybd_event to avoid user suspicion, re-registers the hotkey, and writes captured keystrokes to a file.
Proof-of-concept Windows hotkey-based keylogger. It abuses the RegisterHotKey API to register individual keys as global hotkeys, captures resulting WM_HOTKEY messages, records virtual-key codes to a file, and uses UnregisterHotKey plus keybd_event to replay keystrokes transparently to the user before re-registering each key.
WindowsのRegisterHotKey APIを悪用して多数のキーをグローバルホットキーとして登録し、WM_HOTKEYメッセージからvirtual-key codeを取得してキー入力を記録するホットキー型キーロガー。ユーザーに気付かれにくくするため、キー取得時に一時的にUnregisterHotKeyで登録解除し、keybd_eventでキーを再送してから再登録する。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.