KeyBoy

Malware updated 15 days ago (2024-11-29T14:28:14.361Z)
Download STIX
Preview STIX
Keyboy is a malicious software (malware) that has been used for cyber espionage since 2011. It's primarily associated with the Advanced Persistent Threat (APT) group known as Tropic Trooper, also referred to as Pirate Panda and KeyBoy. This malware infiltrates systems through suspicious downloads, emails, or websites, often without the user's knowledge. Once installed, it can steal personal information, disrupt operations, or even hold data hostage for ransom. KeyBoy has various functionalities, including screen grabbing, determining public or WAN IP addresses, gathering extended system information, launching interactive shells for communicating with the victim machine, downloading and uploading functionality, and using custom SSL libraries for masquerading Command and Control (C2) traffic. The APT group Tropic Trooper, which utilizes KeyBoy, has been active since 2011 and has mainly targeted Tibetan entities. However, there have been observed historical correlations between this group and TA413, another threat actor, indicating some degree of operational overlap. The ShadowPad malware, known to be used by at least five additional groups, including KeyBoy, Tick, Tonto Team, IceFog, and TA428, further demonstrates the interconnectedness of these threat actors. The development cycle of KeyBoy appears to be iterative, updated only as much as necessary to ensure its survival against antivirus detection and basic security controls. Persistence is achieved through the WinLogon\Shell registry key, installed by the dropper’s execution of the Install export from the KeyBoy DLL. The configuration file used by this version of KeyBoy is written to disk as %localappdata%\cfs.dat by the dropper, similar to previous samples. As of February, the last observation of activity related to KeyBoy was reported.
Description last updated: 2024-11-28T11:43:55.869Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Tropic Trooper is a possible alias for KeyBoy. Tropic Trooper, also known as KeyBoy and Pirate Panda, is an Advanced Persistent Threat (APT) group that has been active since 2011. This China-linked threat actor has been involved in numerous malicious activities, including espionage campaigns targeting Middle Eastern government entities and attac
3
Pirate Panda is a possible alias for KeyBoy. Pirate Panda, also known as Tropic Trooper and Keyboy, is a recognized threat actor in the realm of cybersecurity. This group has been active since 2011 and has demonstrated malicious intent through various operations, primarily focused on targeting Tibetan infrastructure. The term 'threat actor' re
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.