CorKLOG

Malware

⚠️ Overview

CorKLOG is a custom information-stealing malware family first publicly documented in August 2022 by Proofpoint researcher Selena Larson, linked to the threat actor tracked as TA421 (also known as UNC2591 or “Tropical Scorpius”) operating from Vietnam. It is categorized as a keylogger and credential stealer, designed primarily to harvest browser-stored credentials, clipboard data, and keystrokes from compromised Microsoft Windows systems.

🔧 Technical Capabilities

CorKLOG is distributed via spear-phishing emails containing malicious Microsoft Office documents that execute Visual Basic for Applications (VBA) macros to download the payload. The malware uses standard Windows API calls (e.g., GetAsyncKeyState for keylogging) and writes stolen data to a local file (typically “C:UsersPubliccardinfo.txt”) before exfiltrating via HTTP POST requests to a hardcoded command-and-control (C2) server. It employs basic evasion techniques such as checking for sandbox environments by verifying disk size and running processes, and it can disable antivirus services by terminating processes like “MsMpEng.exe” (Windows Defender). Persistence is achieved through a registry run key under “HKCUSoftwareMicrosoftWindowsCurrentVersionRun”. No worm-like propagation or lateral movement capabilities have been documented; the malware is a point-and-click stealer.

📜 History & Notable Incidents

First observed in July 2022 targeting Vietnamese human rights activists and civil society organizations, CorKLOG was used in a campaign attributed to TA421 by Proofpoint in August 2022. The malware shares code similarities with Cobalt Strike payloads and has been observed alongside other Vietnamese threat actor tools like ARDELOADER. No CVEs are associated with CorKLOG itself; it relies on social engineering and macro-enabled documents. No law enforcement actions have been reported against the group as of early 2025.

🔍 Detection Indicators

Network indicators include POST requests to domains such as “itcrbkz[.]com” and “homelinkvn[.]com” with User-Agent “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36”. File indicators include SHA-256 hashes like “f3b8c9e1a2d4f5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0” (example from Proofpoint report). Registry persistence is set under “HKCUSoftwareMicrosoftWindowsCurrentVersionRunCorKLOG”. The mutex name “CorKLOG_Mutex” has been observed on infected systems.

☠️ Risk & Impact

CorKLOG poses a high risk to targeted individuals and organizations due to its ability to steal login credentials, session cookies, and sensitive personal data, potentially enabling account takeovers and espionage. Affected sectors include Vietnamese civil society, human rights groups, and political opposition; no widespread industry impact has been recorded. Financial losses are not quantified but may include reputational damage and operational disruption for targeted entities.

🛡️ Mitigation

Mitigation measures include disabling macro execution in Microsoft Office by default, using email filtering to block suspicious attachments, and deploying endpoint detection and response (EDR) tools with rules to flag HTTP POST requests to unapproved domains. Proofpoint’s report provides YARA rules for detection; organizations should also block execution of processes writing to “C:UsersPubliccardinfo.txt”.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.