PSLogger is a Windows surveillance malware utility associated with financially motivated intrusions against banking and financial-sector organizations, including activity linked by multiple researchers to North Korean threat operations. It has been observed in both DLL and standalone executable forms and is used primarily as a post-compromise collection tool rather than as a full remote-access platform.
Its core functions are keylogging and desktop screenshot capture. Observed variants record keystrokes using standard Windows keyboard-state APIs, collect clipboard or process-context data, capture the desktop, compress screenshot output, and store the resulting artifacts locally in temporary user-accessible directories. Some variants encrypt logged keystrokes or encode internal strings and file paths, but the malware is generally considered relatively unsophisticated.
PSLogger has been delivered through PowerShell-based loaders and executable injectors, including use of reflective PE injection techniques and modified open-source tooling. In one documented deployment, a PowerShell script decoded and injected a DLL variant; another related sample appeared as a standalone executable built from the same codebase. Technical overlaps across variants include shared naming conventions, reused screenshot and compression components, and similar local storage behavior.
No built-in command-and-control mechanism has been identified in the analyzed PSLogger variants. The absence of native C2 strongly suggests the malware is intended for long-term monitoring on already compromised hosts, with logs and screenshots later retrieved through other attacker access channels or manual collection. PSLogger has been discussed alongside broader intrusion sets involving PowerShell backdoors, injectors, and banking-focused operations such as SWIFT theft and FASTCash-related activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
PSLogger Keylogger/Screenshot Grabber... The keylogger and screen grabber is delivered via PowerShell and executable injectors... Based on the decoded function names present within the backdoor, a completed version would be expected to support: ... Keylogging
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A keylogger referenced among DPRK indicators of compromise in attacks targeting financial institutions, discussed as part of overlapping reporting connected to the same activity cluster as the PowerShell malware.
A likely DPRK-linked post-compromise surveillance utility observed in two variants: a DLL delivered via a modified PowerSploit reflective injection script and a standalone executable. It logs keystrokes and clipboard data, captures desktop screenshots, compresses them with XZip, and stores the output locally in temp directories for later manual retrieval. The malware lacks an embedded C2 channel and appears intended for long-term monitoring on compromised hosts.
A keylogger and screenshot capture tool delivered via PowerShell and injectors, storing zipped screenshots and keystroke logs on victim systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.