logo

Detecting Hotkey-Based Keyloggers Using an Undocumented Kernel Data Structure

ID: 53cbde84-c059-5873-9d26-2e092adcc869

STIX ID: report--53cbde84-c059-5873-9d26-2e092adcc869

Feed Name: Elastic Security Labs

Threat Score
50/100

Date Published: 2025-03-04

Date Updated: 2026-04-27

...
...

This report analyzes hotkey-based keyloggers that hijack RegisterHotKey to capture keystrokes stealthily, demonstrates a Proof-of-Concept (Hotkeyz), and presents a kernel-mode detection method that inspects an undocumented win32k hash table (gphkHashTable) to enumerate registered hotkeys and identify keylogger activity; the authors provide a driver-based detector and publish code and a demo video.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.