KEYLIME is a Trojan used by APT38, a North Korean state-sponsored threat group known for financially motivated intrusions against banks and other financial institutions. It captures keystrokes and collects clipboard contents from compromised machines, providing visibility into user input and copied information. KEYLIME is also associated with the BlueNorOff malware arsenal. Its documented functionality centers on input collection; fraudulent SWIFT transactions and destructive activity are features of the associated actors’ broader operations, not established capabilities of KEYLIME itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family associated with BlueNorOff operations.
Listed in the APT38 advisory's malware and tool inventory; individual capabilities are not described.
Trojan used to capture keystrokes.
A trojan used to collect data from the clipboard.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.