Unraveling Sparkling Pisces’s Tool Set: KLogEXE and FPSpy
ID: db78ea1a-0b48-5c6b-8980-bd0eb4c00fcb
STIX ID: report--db78ea1a-0b48-5c6b-8980-bd0eb4c00fcb
Feed Name: Palo Alto Networks Unit 42
Unit 42 analyzed two undocumented malware samples attributed to the North Korean APT Sparkling Pisces (Kimsuky): a C++ keylogger named KLogEXE that captures keystrokes, running applications and mouse clicks and exfiltrates data via HTTP, and a DLL backdoor variant called FPSpy that collects system data, downloads encrypted modules, executes commands, and persists under user directories; the report maps shared infrastructure, provides file and domain indicators, and outlines protections and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
