MC Keylogger is a Windows surveillance and theft module used within the OkoBot malware framework, a multi-stage crimeware operation focused heavily on cryptocurrency users and other sensitive-data targets. It functions primarily as a keylogger but extends beyond keystroke capture to collect clipboard contents, monitor USB device connections, and take periodic screenshots. Reported clipboard collection includes copied text, images, and file references, giving the operator visibility into user activity and potentially sensitive material handled outside browser forms.
MC Keylogger is deployed as one of several post-compromise components delivered after initial access is established by the broader OkoBot intrusion chain. That chain has used ClickFix lures and trojanized software distributed through GitHub repositories masquerading as legitimate tools. Earlier stages associated with TookPS and the OkoBot framework establish remote access, gather host information, suppress some defensive visibility, and deliver additional modules, after which MC Keylogger is installed alongside other implants such as SeedHunter, OkoSpyware, and browser-focused theft tooling.
The malware’s role in the framework is persistent user surveillance and collection of operator-relevant artifacts from infected endpoints. Its capabilities support theft of credentials, cryptocurrency-related information, and other sensitive data by capturing typed input, copied material, removable-device activity, and regular screen images. In observed OkoBot operations, artifacts collected by MC Keylogger were later exfiltrated by framework components and removed from disk after upload. Victimology associated with the broader campaign indicates global reach, with notable concentrations in Brazil, Vietnam, Canada, Mexico, and Türkiye. Attribution of the overall operation has not been confirmed, though reporting has noted overlaps with Russian-speaking cybercriminal ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
MC Keylogger : Records keystrokes and clipboard activity, including copied text, images, and file paths, and can also monitor for USB connections and take screenshots every 5 minutes.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A keylogger module that captures keystrokes, clipboard contents, screenshots, and USB connection activity.
A monitoring component that captures keyboard input, clipboard contents, USB device activity, and periodic screenshots.
A keylogger module that records keystrokes, clipboard contents, connected USB devices, and periodic screenshots, storing artifacts for later exfiltration.
A keylogger module that records keystrokes, clipboard contents, connected USB devices, and periodic screenshots, storing artifacts for later exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.