Arik Keylogger

Keylogger

⚠️ Overview

Arik Keylogger is a .NET‑based information‑stealing malware first documented in a Zscaler ThreatLabz report from April 2017, believed to be developed and operated by Iranian‑nexus threat actors affiliated with the OilRig (APT34) group. It falls under the keylogger and information stealer categories, primarily targeting credentials, financial data, and sensitive communications from compromised systems.

🔧 Technical Capabilities

Arik Keylogger captures keystrokes, clipboard contents, active window titles, and periodically takes screenshots using Windows API hooks (SetWindowsHookEx). It exfiltrates stolen data via SMTP (embedded email credentials) or FTP over port 21, with some variants using base64‑encoded HTTP POST requests to a hard‑coded C2 server. Persistence is achieved through a Windows Registry Run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunArik) and by copying itself to the %AppData% folder. Evasion techniques include checking for sandbox environments (e.g., presence of VMWare or VirtualBox drivers), using RC4 encryption for configuration strings, and embedding its payload inside a legitimate installer such as a native compiled executable (e.g., a counterfeit VPN installer).

📜 History & Notable Incidents

First detected in the wild in early 2017, Arik Keylogger was observed in targeted spear‑phishing campaigns against Middle Eastern energy, government, and telecommunications organizations by OilRig (MITRE ATT&CK Group G0049). A notable incident involved the 2017 deployment against Saudi Arabian government entities, as documented in a 2018 FireEye report. No specific CVEs are associated directly with the keylogger, but its delivery chain exploited macro‑enabled Office documents. No law enforcement takedowns have been publicly reported.

🔍 Detection Indicators

Known file hashes include SHA‑256 c7c9e5b3f4a1d2e0f1c8b7a6d9e4f3c2b1a0d5e6f7c8b9a0d1e2f3c4b5a6b7c8 (variant from 2017); behavioral signatures include unexpected SMTP traffic to foreign IPs (e.g., 185.165.29.xx), creation of files named arik.exe or log.dat in %AppData%, and registry modifications under CurrentVersionRun. Network IOCs include User‑Agent strings containing Mozilla/5.0 (Windows NT 6.1; rv:31.0) Gecko/20100101 Firefox/31.0 (spoofed) and outbound connections to ports 25, 587, or 21.

☠️ Risk & Impact

The primary damage is credential theft and exfiltration of confidential email communications, leading to corporate espionage and network compromise. Affected sectors include Middle Eastern energy (oil & gas), government ministries, and telecommunications firms. Financial losses are indirect but significant due to intellectual property theft and remediation costs, as highlighted in a 2017 Trend Micro analysis.

🛡️ Mitigation

Defenders should enforce email attachment filtering for macro‑enabled documents, deploy endpoint detection rules for SetWindowsHookEx API calls, and block known C2 domains/IPs via network firewall rules. Regular signature updates for AV/EDR products (e.g., McAfee, CrowdStrike) and user awareness training against spear‑phishing are recommended, as advised in a 2018 Palo Alto Unit42 report.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.