logo

Unraveling Sparkling Pisces’s Tool Set: KLogEXE and FPSpy

ID: db78ea1a-0b48-5c6b-8980-bd0eb4c00fcb

STIX ID: report--db78ea1a-0b48-5c6b-8980-bd0eb4c00fcb

Feed Name: Palo Alto Networks Unit 42

Threat Score
85/100

Date Published: 2024-09-26

Date Updated: 2026-04-28

Author: Daniel Frank and Lior Rochberger

...
...

Unit 42 analyzed two undocumented malware samples attributed to the North Korean APT Sparkling Pisces (Kimsuky): a C++ keylogger named KLogEXE that captures keystrokes, running applications and mouse clicks and exfiltrates data via HTTP, and a DLL backdoor variant called FPSpy that collects system data, downloads encrypted modules, executes commands, and persists under user directories; the report maps shared infrastructure, provides file and domain indicators, and outlines protections and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.