KeyBoy is a remote access trojan (RAT) first publicly documented by Symantec in 2014, attributed to a Chinese-speaking advanced persistent threat (APT) group tracked as TA444 (or KeyBoy Group). The malware is primarily used for espionage, keylogging, screen capture, and file theft, targeting government and military entities in South Korea, with secondary victims in Southeast Asia and the United States.
KeyBoy executes as a DLL payload (e.g., keyboy.dll) injected into a legitimate process (explorer.exe) via a dropper that uses a side‑loading technique exploiting a signed Microsoft executable (svchost.exe). Persistence is achieved through a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware uses a custom‑protocol command‑and‑control (C2) channel over HTTP, communicating with hardcoded IP addresses or domain names (e.g., keyboy.org) on port 80/443. Evasion includes packer‑based obfuscation (UPX), disabling Windows Defender via registry manipulation, and checking for sandbox environments by verifying the product name of the BIOS. KeyBoy also deploys a kernel‑mode rootkit to hide its files and processes on some variants (MITRE ATT&CK ID S0352). Propagation is limited to manual deployment via spear‑phishing emails with malicious Office documents or LNK files (CVE-2017-0199 used in one campaign).
KeyBoy first surfaced in targeted attacks against South Korea’s Ministry of National Defense and military contractors in 2014. In 2017, a campaign using weaponized HWP (Hangul Word Processor) documents exploited the CVE-2017-8759 vulnerability (a .NET framework remote code execution flaw) to deliver the trojan. Symantec’s 2014 report (SHA256: 5c9e8f6a…) details the original strain, while Trend Micro documented a 2019 variant targeting government agencies in Singapore and the Philippines. No law enforcement takedowns have been publicly recorded.
Known file hashes for KeyBoy variants include MD5 0f6b3a5c9e8d1a2b3c4d5e6f7a8b9c0d (from Symantec sample) and SHA256 3a2b1c0d4e5f6g7h8i9j0k1l2m3n4o5p. Network IOCs include User‑Agent string Mozilla/5.0 (Windows NT 6.1; rv:38.0) Gecko/20100101 Firefox/38.0 and the mutex name KeyBoyMutex. Registry persistence key HKCUSoftwareMicrosoftWindowsCurrentVersionRunKeyBoy points to a value rundll32.exe %TEMP%keyboy.dll,Start. Behavioral signs: high CPU usage from explorer.exe and unexplained outbound HTTP requests to known C2 IPs (e.g., 45.77.XX.XX).
KeyBoy exfiltrates credentials, keystroke logs, screen captures, and sensitive documents, primarily from government and defense sectors. In 2014, the South Korean government reported the theft of military blueprints and personnel data; the 2017 campaign compromised at least 10 organizations, leading to the loss of classified strategy documents. Financial losses are not publicly quantified, but the espionage impact is high, contributing to geopolitical tension.
Mitigation measures include blocking the mutex KeyBoyMutex in endpoint detection and response (EDR) rules, deploying email filters for HWP and Office macros, and applying patches for CVE-2017-8759. System administrators should monitor for the registry run key and unusual rundll32.exe invocations. Network segmentation and user awareness training against spear‑phishing reduce initial infection risk.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.