KEYMARBLE is a Windows remote access trojan associated with the North Korean Lazarus Group and used in espionage-oriented intrusions. It has been described as a full-function RAT and backdoor capable of long-term surveillance, remote administration, and data theft. Reported functionality includes process enumeration, screenshot capture, collection of host identifiers such as MAC address information, shell command execution, process creation and termination, directory and drive enumeration, file upload and download, file movement, archive creation, secure file deletion, and general system reconnaissance. The malware also supports storing data in the Windows Registry and uses encrypted command-and-control communications, including variants that employ a customized XOR-based scheme; some observed samples also used wolfSSL as part of their communications stack.
KEYMARBLE has been linked to Lazarus tradecraft through code and behavioral overlaps and has appeared alongside other Lazarus malware families in broader DPRK intrusion activity. Observed delivery has included malicious Office documents crafted for targeted victims, with macro-enabled lures used in spearphishing-style infection chains that ultimately deployed updated KEYMARBLE variants. In documented operations, the malware was used against Russian organizations, an unusual victimology for Lazarus, though the family is more broadly associated with North Korean intelligence collection. Its capabilities and operator usage align with post-compromise reconnaissance, collection, persistence, and remote control on compromised Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Related Malware: AppleJeus BADCALL Bankshot BLINDINGCAN Cryptoistic Dtrack KEYMARBLE KiloAlfa SierraAlfa ThreatNeedle Torisma WannaCry
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
the machine’s UID, which is a result of the operation: MD5( ProductID | MAC ), where the first field is obtained by querying the SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId registry key
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Examples include 'Bazar can also check if the Russian language is installed,' 'DropBook has checked for the presence of Arabic language,' 'Maze has checked the language of the infected system,' and 'SynAck ... checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.'
If succeeds, retrieves file size and sends the file content to the server in chunks of 16KB.
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
Each message exchanged between the malware and the server will have a predefined structure... resembles a TLS application record.
Receives 2 paths – a source path and a destination path. The malware will move the file from the source to destination path. | The VBS script downloads a CAB file from the dropzone sever, extracts the embedded EXE file (backdoor) using Windows’ “expand.exe” utility, and finally executes it.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... KEYMARBLE ... (v1.1→v1.2) ...
KEYMARBLE (v1.1→v1.2)
Espionage implant used to support reconnaissance, data theft, and persistent surveillance.
Lazarus-associated malware family listed as related malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.