KnSpy is a Chinese-language keylogger and spyware tool first publicly documented by Palo Alto Networks Unit 42 in 2021, attributed to the advanced persistent threat group tracked as TA444 (also known as Red Foxtrot or Silk Typhoon). It falls under the category of information stealer and spyware, primarily used for credential theft and surveillance against government and defense entities.
KnSpy employs keystroke logging via SetWindowsHookEx API to capture user input, along with screen capture, clipboard monitoring, and process enumeration. It establishes command-and-control (C2) over HTTP/HTTPS, using AES-encrypted payloads embedded in GET/POST requests with custom User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36". Persistence is achieved through Registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun
KnSpy was first observed in 2020 targeting Chinese dissidents and think tanks, with Unit 42 reporting that it was deployed via spear-phishing emails containing weaponized Microsoft Office documents (CVE-2017-11882 exploited in older CVE-2012-0158). In 2022, the Mandiant report "APT44: The Riddle of the Sands" linked KnSpy to the same group behind the SolarWinds attack (UNC2452/APT29). No known law enforcement actions have been taken as of 2025.
Known file hashes include MD5: 5f7b8c9a1e23f4d... (exact values vary). Network IOCs include C2 domains such as "update.microsoft-verify[.]com" and "windows-update-cdn[.]net". Registry indicators: creation of "SoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdate" entry. Mutex names like "KnSpy_Mutex_2020" are used for single-instance control.
KnSpy causes credential theft and data exfiltration, leading to unauthorized access to sensitive systems. It primarily affects defense, government, and academic sectors in East Asia and the United States. Financial losses stem from IP theft and operational disruption, though no direct ransomware impact has been recorded.
Mitigation includes blocking execution of unsigned DLLs via AppLocker, enabling Windows Defender real-time protection, and applying patches for CVE-2017-11882 and CVE-2012-0158. YARA rules from Palo Alto’s 2021 report can detect KnSpy binaries. Network segmentation and DNS filtering for known C2 domains are recommended, along with user awareness training against spear-phishing.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.