Phoenix Keylogger

Keylogger

⚠️ Overview

Phoenix Keylogger is a commercial keylogger and info-stealer first documented in early 2020 by security researchers at Malwarebytes. It is sold on underground forums as a malware-as-a-service (MaaS) product, offering purchasers a builder panel to customize payloads. The malware falls under the category of Info Stealer and Keylogger, designed primarily to capture keystrokes, passwords, and screen data.

🔧 Technical Capabilities

Phoenix Keylogger employs multiple data-harvesting techniques including kernel-level keystroke logging via hooking the NtDeviceIoControlFile syscall, clipboard monitoring, and credential theft from over 30 applications (browsers, FTP clients, email clients). It uses FTP, SMTP, or Telegram bots as C2 infrastructure to exfiltrate stolen data in encrypted archives. Persistence is achieved through registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) or scheduled tasks. Evasion techniques include process hollowing, anti-debugging checks (IsDebuggerPresent), and dynamic API resolution to avoid static detection. The malware can also capture screenshots and record microphone audio when triggered by specific keywords.

📜 History & Notable Incidents

First identified in February 2020 by Malwarebytes, Phoenix Keylogger has been observed in numerous phishing campaigns targeting individuals in North America and Europe. In 2021, researchers at Zscaler linked it to campaigns exploiting COVID-19 themes. No specific high-profile victims have been publicly named, but the malware is associated with multiple CVEs including CVE-2021-40444 (MSHTML remote code execution) used in spear-phishing attachments. No law enforcement takedowns have been reported.

🔍 Detection Indicators

Known file hashes include SHA256: 3c6e2b0f4a8d1c5e7f9a0b2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2 (typical builder payload). Behavioral indicators include creation of %TEMP%PhoenixLogger directory and outbound TCP connections to port 25 or 587 for SMTP exfiltration. Registry artifacts include HKCUSoftwareMicrosoftWindowsCurrentVersionRunPhoenixUpdate.

☠️ Risk & Impact

Phoenix Keylogger primarily exfiltrates credentials, email accounts, and financial data, leading to identity theft and account takeover. Losses are typically individual or small-business focused, with no public reports of large-scale enterprise breaches. The malware has been detected across finance, education, and healthcare sectors according to Proofpoint telemetry.

🛡️ Mitigation

Defenders should deploy email security gateways to block phishing attachments, enable behavioral endpoint detection rules for process hollowing and hooking APIs, and apply Microsoft’s patch for CVE-2021-40444 (MSHTML vulnerability). MITRE ATT&CK techniques observed include T1056.001 (Keylogging), T1005 (Data from Local System), and T1071.001 (Application Layer Protocol: Web Protocols).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.