> For the complete documentation index, see [llms.txt](https://mapol.gitbook.io/home/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mapol.gitbook.io/home/blog/malware-analysis/keylogger/kimalogger.md).

# KimaLogger

In the second quarter of 2025, the AhnLab Security Intelligence Center (ASEC) discovered an operation linked to the well known DPRK state sponsored threat actor group `Kimsuky`, also known as `Velvet Chollima`, which began exploiting the `BlueKeep` and `Microsoft Office Equation Editor` vulnerabilities for initial access.

KimaLogger came into play during the final stage of the operation, with the purpose of stealing credentials from the infected machine.

I found this sample on: [**MalwareBazaar**](https://bazaar.abuse.ch/sample/3af5c9759d95fd6091e665c03406f275fac26afe70db067a785cdc003389efbd/)

<figure><img src="https://cdn-images-1.medium.com/max/1000/1*SDybs3Iu6iYvWV7uWuA41g.png" alt=""><figcaption><p><a href="https://asec.ahnlab.com/en/87554/">AhnLab - Kimsuky Threat Actor Group’s Exploitation of BlueKeep Vulnerability.</a></p></figcaption></figure>

***

### **Table of Contents**

1. [Sample Overview](#sample-overview)
2. Obfuscated Files or Information: Junk Code Insertion (T1027.016)
3. Obfuscated Files or Information: Dynamic API Resolution (T1027.007)
4. Execution Guardrails (T1480)
5. System Time Discovery (T1124)
6. Data Staged: Local Data Staging (T1074.001)
7. Clipboard Data (T1115)
8. Application Window Discovery (T1010)
9. Input Capture: Keylogging (T1056.001)
10. Encrypted Channel: Symmetric Cryptography (T1573.001)
11. Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol (T1048.003)
12. Execution Flow
13. Conclusion
14. IOCs
15. Config Extractor
16. YARA Rule
17. Sigma Rule
18. Additional Resources

***

### **Sample Overview**

The sample was written in C++ using Microsoft Visual Studio 2012 as the IDE, and it was compiled around September 20, 2024.

<figure><img src="https://3275977096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSVMhiBgu1B4d2lBF9L3%2Fuploads%2Ff31FNhRLonIG1Dds1XT1%2Fimage.png?alt=media&amp;token=cc0f2d9c-3a9c-48f5-b171-61ae46165b9a" alt="" width="563"><figcaption><p>Figure 1. Identified the compile time and languages used by the sample.</p></figcaption></figure>

The overall entropy values show that the given sample does not implement any packing methods. However, an obfuscation technique may be implemented within the code.

<figure><img src="https://3275977096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSVMhiBgu1B4d2lBF9L3%2Fuploads%2FwOvqu2TfucPrDdFqr9DG%2Fimage.png?alt=media&amp;token=21dff783-929f-4722-ba19-73c30adba83e" alt="" width="563"><figcaption><p>Figure 3. The overall entropy values show that the given sample is not packed.</p></figcaption></figure>

However, the `.rsrc` section of the sample contains the interesting strings `KLogExe` and `KLOGEXE` within the string table, if applying common sense, this could be indicate to the word `Keylog`.

<figure><img src="https://3275977096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSVMhiBgu1B4d2lBF9L3%2Fuploads%2F1vNu1w3p5lY8FUk9gBSn%2Fimage.png?alt=media&amp;token=9bfa278e-a056-4e32-ab62-19045f706052" alt=""><figcaption><p>Figure 3. Resource strings related to the keyword keylogger.</p></figcaption></figure>

***

### Obfuscated Files or Information: Junk Code Insertion **(**&#x54;1027.01&#x36;**)**

In the `WinMain` function, two `LoadStringW` functions are called to load string resources, where the IDs are different, `103` and `109`. This show that the original code itself may implement an `.rc` file for string resource management.

<figure><img src="https://3275977096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSVMhiBgu1B4d2lBF9L3%2Fuploads%2FA1FKeY5DUpJ4o0G0iyAr%2Fimage.png?alt=media&amp;token=d263b8db-d370-4735-b881-18a7f845d577" alt=""><figcaption><p>Figure 4. Loading a specific string from the resource section.</p></figcaption></figure>

As shown in Figure 5, the strings loaded are `KLogExe` and `KLOGEXE`. As seen in Figure 3 from the [**Sample Overview**](#sample-overview), the loaded IDs are directly related to these words.

<figure><img src="https://3275977096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSVMhiBgu1B4d2lBF9L3%2Fuploads%2FDDlJgzKDSIXjFBbuKWBR%2Fimage.png?alt=media&amp;token=97130013-d8ca-4439-9814-ab4f6fb617f1" alt="" width="521"><figcaption><p>Figure 5. Loaded strings identified as KLOGEXE and KLogExe.</p></figcaption></figure>

After the resource strings are loaded, the `sub_140002A70` function is called. Inside this function, a `WNDCLASSEXW` structure is initialized, the cursor is set to a standard cursor, and the icon is loaded from the `.rsrc` section of the sample. The function then returns the result of `RegisterClassExW` to register the window class for the GUI application.

However, `CreateWindow`, `CreateWindowEx`, or any other functions used to create a GUI application could not be found. This shows that this code was likely just included as a decoy template.

<figure><img src="https://3275977096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSVMhiBgu1B4d2lBF9L3%2Fuploads%2F1odhmeRC1zqwgdE9nBCu%2Fimage.png?alt=media&amp;token=bd72cb40-b614-4722-b3fa-ec39b6e9e88d" alt="" width="563"><figcaption><p>Figure 6. Initializing structure fields for the GUI application.</p></figcaption></figure>

***

### **Obfuscated Files or Information: Dynamic API Resolution (T1027.007)**

Now, the thread for the `sub_140001A00` function begins to be created. In doing so, the string `DsfbufUisfbe` is passed as an argument to a function call to `sub_140001000`.

<figure><img src="https://3275977096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSVMhiBgu1B4d2lBF9L3%2Fuploads%2F8RxsXv4YNvRJ5o1NaubS%2Fimage.png?alt=media&amp;token=fd6a79b0-6723-4de7-a472-f8ca3a9ef0cd" alt=""><figcaption><p>Figure 7. asd</p></figcaption></figure>

Inside the `sub_140001000` function, an array offset at `off_1400193E` is initialized. Also, each value in the array follows the same scrambled pattern as the argument passed in Figure 7.

<figure><img src="https://3275977096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSVMhiBgu1B4d2lBF9L3%2Fuploads%2F1s8XWqtOuZOWloSxOmiK%2Fimage.png?alt=media&amp;token=81f02ad3-44fb-4eb3-8a64-cf4de57a84e1" alt="" width="563"><figcaption><p>Figure 8. asd</p></figcaption></figure>

Before jumping into the deobfuscation process, the string that was passed as an argument to the `sub_140001000` function is checked against each value in the array. If a match is found, the deobfuscation process is performed.

<figure><img src="https://3275977096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSVMhiBgu1B4d2lBF9L3%2Fuploads%2F28umOk92rFvC6EkAtD8J%2Fimage.png?alt=media&amp;token=8b880e46-291c-4900-b0cf-c680bf839cc1" alt="" width="563"><figcaption><p>Figure 9. asd</p></figcaption></figure>

To deobfuscate these strings, a shift-down caesar cipher algorithm is used. This process can be separated into two parts, one for the DLL name, and another for the function name passed as an argument to the `sub_140001000` function.

<figure><img src="https://3275977096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSVMhiBgu1B4d2lBF9L3%2Fuploads%2FWyWuS9icOxcXU42MID2a%2Fimage.png?alt=media&amp;token=b09cb17c-8aa3-4bfb-81f7-ad9ad612e1e9" alt=""><figcaption><p>Figure 10. asd</p></figcaption></figure>

After the strings are deobfuscated, they are used as a library to be loaded. It does this by calling the following functions, `LoadLibraryA` and `GetProcAddress`, the same way dynamic API resolution works in various other APT related malware.

<figure><img src="https://3275977096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSVMhiBgu1B4d2lBF9L3%2Fuploads%2Fb9LnHKUsU8PFL0PYTPpF%2Fimage.png?alt=media&amp;token=b3a3612b-86e2-4e46-aed6-6edf0189778f" alt="" width="563"><figcaption><p>Figure 11. asd</p></figcaption></figure>

***

### **Execution Guardrails (T1480)**

After the thread is created, it checks whether the specified event object, `Norton_BreakHelper613`, already exists using the `OpenEventW` function. If it does, the loop breaks and the newly created thread is deleted, otherwise, the loop continues.

<figure><img src="https://3275977096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSVMhiBgu1B4d2lBF9L3%2Fuploads%2F7VTuHjF3xzWpfWtWjeyb%2Fimage.png?alt=media&amp;token=a099c575-39ed-4ba7-b886-62e656678bc8" alt="" width="365"><figcaption><p>Figure 12. asd</p></figcaption></figure>

***

### **System Time Discovery (T1124)**

lorem

***

### **Additional Resources**

<https://attack.mitre.org/>

<https://asec.ahnlab.com/en/87554/>

<https://github.com/hackedteam/core-win32><br>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://mapol.gitbook.io/home/blog/malware-analysis/keylogger/kimalogger.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
