PseudoManuscrypt is a Windows spyware-oriented trojan and remote surveillance malware family first identified in 2021. It was named for similarities between its loader and the Lazarus-associated Manuscrypt loader, but public reporting has not established a reliable attribution to Lazarus. The malware was distributed at scale through a malware-as-a-service ecosystem that abused fake pirated software installers, cracked software lures, and search-engine-optimized malicious download sites. Some campaigns also used broader criminal distribution channels and, in some cases, infrastructure associated with other malware operations. Victimology was global and included government organizations, industrial enterprises, military-industrial entities, research laboratories, and a notable share of industrial control system and engineering workstations.
PseudoManuscrypt uses a multi-stage infection chain in which an installer or loader deploys an encrypted core payload, stores payload data in the Windows registry, and establishes persistence through a Windows service. Variants have used DLL-based loaders, in-memory execution, and injection into svchost.exe service processes. The malware also attempts to weaken host defenses by adding exclusions to Microsoft Defender and, in later variants, by terminating security products and deleting security-service configuration data.
The family provides broad espionage and post-compromise functionality. Reported capabilities include keylogging, clipboard theft, theft of VPN connection information and potentially saved credentials, collection of Windows event logs, screen capture and screen-video recording, microphone recording, host and network reconnaissance, process and port enumeration, and theft of credentials from selected regional applications. It can also receive commands to download and run additional payloads, clear event logs, modify the hosts file, update itself, and remove itself. These features give operators extensive visibility into and control over infected systems.
PseudoManuscrypt command-and-control traffic has been observed over UDP using a KCP-based transport, with TCP fallback in some variants. Researchers also documented custom protocol layers above the transport and fallback domain-generation behavior when primary command-and-control infrastructure is unreachable. Technical overlaps have been noted with KCP-based tooling previously discussed in connection with Chinese threat activity, and some samples contained Chinese-language development artifacts, but attribution remains uncertain.
The campaign stands out for combining opportunistic mass distribution with high-value victim sectors, especially industrial and engineering environments. This blend of broad criminal-style delivery and deep surveillance capability has led multiple researchers to assess PseudoManuscrypt as a significant espionage threat, including possible industrial-espionage use cases.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We dubbed the newly-identified malware PseudoManuscrypt. The PseudoManuscrypt loader makes its way onto user systems via a MaaS platform that distributes malware in pirated software installer archives.
We dubbed the newly-identified malware PseudoManuscrypt. The PseudoManuscrypt loader makes its way onto user systems via a MaaS platform that distributes malware in pirated software installer archives.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Finally, the malware adds itself to the exclusions list of the Windows Defender antivirus solution by modifying the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths. | the malware used in the attack loads its payload from the system registry and decrypts it. The payload’s location in the registry is unique for each infected system.
Finally, the malware adds itself to the exclusions list of the Windows Defender antivirus solution by modifying the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths. | the malware used in the attack loads its payload from the system registry and decrypts it. The payload’s location in the registry is unique for each infected system.
Keylogger. Enables the malware to intercept the codes of keys pressed by the user on the keyboard.
Stealing VPN connection data. The malware gets the contents of the Windows service files used to store data on VPN connections configured on the infected system
Collecting network connection data. The malware collects the names of network adapters, as well as connection type information
the malware also records the name of the application window in which the data was entered
Collecting information on processes that accept network connections on TCP and UDP ports.
compression_type can be one of the following... 0x3F -> zlib compression, then L1 xored with 0x88
Data collected by the malware is sent to the malware command-and-control server... The KCP protocol is used to connect to the server.
this family communicates using KCP over UDP, and TCP as a fallback.
The file 2.exe uses the link hxxps://google[.]diragame[.]com/userf/3002/gogonami.exe to download the main PseudoManuscrypt module
149 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware-as-a-service stealer focused on browser cookies, with keylogging and cryptocurrency theft capabilities via ClipBanker, and plugin download support over KCP.
Malware family referenced as using Gh0stKCP for C2 transport.
PseudoManuscrypt is described as a malware family that uses the Gh0stKCP protocol over UDP for command-and-control communications.
A malware family observed as one of the payloads distributed by PrivateLoader.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.