Elastic Security Labs detailed a Windows keylogging technique that abuses the RegisterHotKey API to register individual keys as global hotkeys and collect the resulting WM_HOTKEY messages. The Hotkeyz proof of concept temporarily unregisters a captured hotkey, replays the user’s original keystroke via keybd_event, re-registers the hotkey, and records its virtual-key code, allowing keystroke collection with little visible disruption.
The researchers found that Event Tracing for Windows does not produce telemetry for RegisterHotKey or UnregisterHotKey, limiting direct API-based detection. They instead created a kernel-driver-based detector that examines the undocumented gphkHashTable structure in win32kfull.sys for excessive alphanumeric hotkey registrations; registering 36 or more unmodified alphanumeric keys is identified as a likely indicator of hotkey-based keylogging. Elastic released the detector and demonstrated that it detects Hotkeyz.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Elastic Security Labs presented its research on detecting Windows hotkey-based keyloggers, including the kernel-memory inspection approach and Hotkeyz detection demonstration, at NULLCON Goa 2025.
Elastic Security Labs released a GitHub proof-of-concept detector that scans the undocumented win32kfull.sys gphkHashTable structure for broad individual alphanumeric hotkey registrations. The detector alerted on Hotkeyz using a threshold of 36 unmodified alphanumeric hotkeys.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
learn.microsoft.com
Open sourceelastic.co
Open sourcelearn.microsoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.