Unit 42 identified ten strains of info-stealers popular with SilverTerrier: AgentTesla, Atmos, AzoRult, ISpySoftware, ISR Stealer, KeyBase, LokiBot, Pony, PredatorPain, and Zeus.
KeyBase
KeyBase is a commercial Windows information stealer and keylogger written in C# for the .NET Framework, first observed in February 2015.
KeyBase
Family profile
KeyBase is a commercial Windows information stealer and keylogger written in C# for the .NET Framework, first observed in February 2015. Originally sold for approximately US$50, it remained in circulation after its author stopped selling it. Multiple criminal groups have deployed KeyBase, including Nigerian business email compromise actors tracked as SilverTerrier.
KeyBase steals credentials from web browsers and email clients, records Unicode keystrokes and the associated foreground window, collects clipboard contents, and captures screenshots. It uses embedded NirSoft password-recovery utilities, including MailPassView and WebBrowserPassView, which are stored in AES-encrypted form and extracted and executed when needed. Configurable features include application-triggered screenshots, downloading and executing additional files, and a time-limited self-destruct function. Persistence is established through Windows startup mechanisms or a per-user autorun registry entry. Internal strings are obfuscated or encrypted, while stolen information is transmitted over unencrypted HTTP to a web-based management interface called Keypanel. Some panel deployments exposed victim screenshots without authentication and contained insecure upload functionality.
Distribution primarily uses phishing emails with business-themed lures involving purchase orders, quotations, invoices, shipping documents, and payments. Payloads have arrived as archived executables, malicious Office documents, and through Office exploit kits. One documented Excel-macro infection chain used an Event Viewer registry-hijacking technique to bypass Windows User Account Control before executing KeyBase. Infections have affected organizations worldwide, including manufacturing, transportation and logistics, wholesale and retail, engineering, high technology, education, and hospitality. KeyBase has also appeared in multistage infection chains involving BloodyStealer.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Keylogging
- Persistence
Samples
Recent samples
129 sandbox samples in the Derp library, newest 24 shown
5e9157966b35e7db749f962da7587710d7adc02af8e475fa02f21f886de69203 34065d54b9385d0e1f47e09f16d0517014d60280811b036fb75f30be50f29958 83a5d1c000c3054a70c570e8de3dd994e838e093cd34206f8f409ed34fc27328 7cd51965b0a0556db51057df797978a1bb9b4e28f7fe2049b5826babd97e4a5e fb0fba4ab0b4445f152a8c4413cb5f65df0584442fe64cdf5bd934f33a59f37a 9007150046115c4af15248cce9577eae3b2feb47ecbe6fe84447d36a8a0b9dad e5ddbcabf5cc366403d3119ad5dd315a6fac325eed45f5ee31ac4d494492b87c 68c7898f79e1ac8083044dd0aa20b1d37b54ad4a113b009e1468d983e745f0ed a0e28ee167a364fd1b9777b2d9f67d5cc1b01e840992a7ff2e7889f4dfb73d74 031d5d75e3d0df0d008d8927152af4930123c5a4665256c4eecf08d0bd25eab8 d997d2d519552ad01b9e5f665c3fdaae0ec9cf566276832677acedff812740b0 c8992754918ad470af29c8e06d357ee300676ff2088739ef4fa31e7c754257b4 c61ef4c173d1d3c598ecbf315e91295421cd666711da2c33a2f74fe7b4880781 03c1faaf8ed9d74cbd009cb980cfa1f2bcc94cc04eac696be9749c521d98ec36 b8d46168ee21a44533e4d11ff1db950686feccaf8c1a459f16d9facd063bc2ea e7c41f9adfeef75cac1725189a2700bf64f07a4c5b8bfbbbd6d9d0418bb0c879 893915077a5c8f59c751fbb76ac151ba675c63c58d9e552c2f362e385f6a02cb 6ddc187c125f2ef8b6a0d651220214306adbf2fa6b4f140f146932bae18cbb37 c177b8fc8c088deea7e5f4b800fb07aab1cfdba4cb812cb070887912094d3f6d 92819f8cf07736876a0aba4ada9d509a952d7d313060f52c97fdb97749911133 2e67b33c252dfa655d2faa2cf54c964c093c5c07698f9ba6bada35674fb4ce3b c556c5344a1d4b81769be53ea525e2566a719627b830a83bdeb000449a7253dc c8660840f74a17d2b5e5d44e62a737773b80b57300bf940d09a8401dc983924d ce8b3e7507ef52a70988723dbc3d2d766d3c4cabe58c601505b3722ab3c9a23d Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
KeyBase in ATT&CK
17 distinct techniquesTechniques
17 techniquesReporting
Research mentioning KeyBase
Sophos News - The Sophos Blog
Researchers reported that the KeyBase credential-stealing trojan continued to spread widely even after its public takedown, with attackers distributing it through phishing emails and Office exploit kits. The malware steals browser and email passwords, logs keystrokes and clipboard data, captures screenshots, and uploads stolen information to a web management panel known as Keypanel. Analysis of exposed infrastructure found 82 active panels across 64 websites, 933 infected Windows systems, and 125,083 screenshots, showing that operators were still actively collecting data from victims. The exposed screenshots and panel data revealed heavy targeting in India, China, South Korea, the United Arab Emirates, Indonesia, Bangladesh, and Djibouti, with manufacturing, transportation, hospitality, education, and business operations among the affected sectors. Researchers linked campaigns to phishing lures such as purchase orders and aviation-themed messages, and found evidence that attackers used embedded Nirsoft tools including MailPassView and WebBrowserPassView, stored in AES-encrypted form and unpacked at runtime, alongside obfuscated strings and compromised email accounts. The stolen material included banking activity, cargo and purchase-order details, hotel guest information, educational records, and other data consistent with credential theft, invoice fraud, and supply-chain compromise.
BloodyStealer and gaming assets for sale | Securelist
Researchers reported that BloodyStealer, a low-cost information-stealing malware sold on a Russian-speaking underground forum, was being used to harvest browser data, system details, and active sessions from gaming and messaging platforms. The malware specifically targeted services including Steam, Origin, Epic Games, GOG, Bethesda, Telegram, and VimeWorld, and used anti-analysis features, victim fingerprinting, command-and-control communications, and ZIP-based data exfiltration to steal data from infected systems. The stolen data fed a broader criminal marketplace where gaming logs, compromised accounts, in-game items, and phishing kits were bought and sold for profit. Researchers said the malware appeared in multistage infection chains alongside threats such as KeyBase and Agent Tesla, with detections across Europe, Latin America, and APAC, primarily affecting home users as attackers monetized virtual goods, account access, and gaming-related credentials through wholesale and retail underground sales.