WINGHOOK is a shared-library keylogger targeting Linux and Unix-based operating systems. It hooks the read and fgets functions to intercept user input within the process that loads it. Captured keystrokes and host and user information are stored locally in encoded or encrypted logs. A companion utility, WINGCRACK, decodes and displays the captured data.
WINGHOOK has been deployed by the financially motivated threat actor UNC2891 in banking intrusions involving ATM switching and related infrastructure, including Indonesian banks. Observed deployments used modified SSH binaries to load the malicious shared library, enabling input capture within SSH processes. Encoded and encrypted logging helps conceal the collected information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WINGHOOK is a Linux .so-library with a capability to intercept user’s keystrokes from a process in which WINGHOOK is loaded.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
"UNC2891 deployed a range of custom malware, including CAKETAP (a Solaris/Linux rootkit)... attackers maintained undetected access for years"
The threat actor employed multiple obfuscation techniques, including payload and string encryption.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Keylogger used by UNC2891 to capture credentials/keystrokes on compromised hosts.
Shared-library keylogger loaded into SSH processes through modified binaries and library-loading mechanisms. It hooks fgets and read to intercept input, recording captured data alongside host and user information in encrypted files, commonly /var/tmp/.zmanDwJ2Og. UNC2891 used it to harvest credentials supporting lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.