logo

iSpy Keylogger

ID: a065ae48-0c38-585f-a03c-67139c1d0666

STIX ID: report--a065ae48-0c38-585f-a03c-67139c1d0666

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ analyzed a commercial .NET keylogger called iSpy that is distributed via spam attachments and packed with various packers and crypters. iSpy uses anti-analysis and anti-VM checks, employs process hollowing to load its .NET payload, achieves persistence via Run registry entries, disables AV processes through Image File Execution Options manipulation, and steals keystrokes, saved credentials, screenshots and webcam images, exfiltrating data via HTTP/SMTP/FTP to attacker-controlled hosts; the report includes multiple MD5s and a sample URL as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.