Researchers reported that the KeyBase credential-stealing trojan continued to spread widely even after its public takedown, with attackers distributing it through phishing emails and Office exploit kits. The malware steals browser and email passwords, logs keystrokes and clipboard data, captures screenshots, and uploads stolen information to a web management panel known as Keypanel. Analysis of exposed infrastructure found 82 active panels across 64 websites, 933 infected Windows systems, and 125,083 screenshots, showing that operators were still actively collecting data from victims.
The exposed screenshots and panel data revealed heavy targeting in India, China, South Korea, the United Arab Emirates, Indonesia, Bangladesh, and Djibouti, with manufacturing, transportation, hospitality, education, and business operations among the affected sectors. Researchers linked campaigns to phishing lures such as purchase orders and aviation-themed messages, and found evidence that attackers used embedded Nirsoft tools including MailPassView and WebBrowserPassView, stored in AES-encrypted form and unpacked at runtime, alongside obfuscated strings and compromised email accounts. The stolen material included banking activity, cargo and purchase-order details, hotel guest information, educational records, and other data consistent with credential theft, invoice fraud, and supply-chain compromise.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
By February 2016, Unit 42 had identified 64 websites hosting 82 active KeyBase web panels, tied to 933 infected Windows systems and 125,083 screenshots exposed through unauthenticated panel storage.
In June 2015, Unit 42 said it had previously reported on the KeyBase malware family after its initial emergence.
Unit 42 reported that the KeyBase malware family first appeared in February 2015, marking the beginning of observed activity for the credential-stealing trojan.
Sophos found multiple KeyBase server-side panel installations on the jobme.eu server and linked specific malware samples to panel folders including "roko" and "ocha."
Sophos documented KeyBase being widely distributed during 2015–2016 through Office exploit kits and phishing emails carrying archived Windows executables.
A healthcare company suffered repeated KeyBase infections on September 7, September 10, and September 13, with the final phishing email apparently sent from an internal company email account.
Unit 42 observed that KeyBase use grew significantly after June 2015 even though active development appeared to have stopped and the public takedown had occurred.
The original KeyBase project and website were taken down after increased criminal use, and the author reportedly claimed to stop selling the malware. Despite this, new samples and downloads remained available afterward.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 61 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
nakedsecurity.sophos.com
Open sourcevirusbulletin.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.