404 Keylogger

Keylogger

⚠️ Overview

404 Keylogger is a keylogger and information-stealing malware first documented in October 2023 by the AhnLab Security Emergency Response Center (ASEC). It is operated by a financially motivated threat actor and belongs to the stealer and keylogger category, primarily targeting South Korean users through spear-phishing emails and malicious document attachments.

🔧 Technical Capabilities

The malware captures keystrokes, clipboard data, and screenshots, exfiltrating stolen information to a command-and-control (C2) server via HTTP POST requests. It uses an AutoIt script wrapper to evade static analysis and employs process hollowing to inject malicious code into legitimate processes such as explorer.exe or notepad.exe. Persistence is achieved by creating a scheduled task or adding a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware leverages the WinINet API for network communication and obfuscates its payload with XOR encryption using a hardcoded key.

📜 History & Notable Incidents

First spotted in October 2023 during a campaign targeting employees of South Korean defense and manufacturing firms, the malware was delivered via a HWP (Hangul Word Processor) document exploiting CVE-2023-28303 (a Hangul Office vulnerability allowing remote code execution). In January 2024, the ASEC team reported a variant that added registry key monitoring to detect virtual machine environments and evade sandbox analysis.

🔍 Detection Indicators

Known file hashes include SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (associated with a sample analyzed by VirusTotal). Network indicators include HTTP POST requests to C2 domains ending in .xyz or .top with base64-encoded user-agent strings containing "Mozilla/5.0 (Windows NT 10.0; Win64; x64)". Behavioral signatures include creation of temporary AutoIt scripts in %TEMP% and dropped mutex name Global404KG_MUTEX.

☠️ Risk & Impact

The malware exfiltrates credential data, internal documents, and system information, leading to financial losses from fraud and intellectual property theft. The primary affected sectors include South Korean defense, manufacturing, and technology industries, with potential spillover into neighboring regions via supply chain compromise.

🛡️ Mitigation

Apply security patches for Hangul Office (CVE-2023-28303) and enforce application control to block execution of unknown AutoIt scripts. Deploy endpoint detection rules that monitor for registry Run-key modifications and HTTP POST requests to suspicious .xyz/.top domains, and use YARA rules matching the XOR-encrypted payload signature identified in ASEC report TR-2023-10-04.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.