Executive Summary
KEYMARBLE is a Windows trojan reportedly used by North Korean threat actors. It establishes persistent remote access, extracts credentials, and exfiltrates data from compromised hosts. The malware’s use in targeted campaigns against government entities underscores its potential for high‑impact espionage.
Enhanced Description
KEYMARBLE is a Windows‑based Trojan that has been attributed to the North Korean government by US-CERT (citation: US‑CERT KEYMARBLE Aug 2018). The malware operates as an espionage tool, typically compromising privileged accounts and creating a foothold for further lateral movement within corporate or governmental networks. While publicly available samples are scarce, field observations suggest that it follows standard trojan behavior models: persistence mechanisms, covert data exfiltration, and remote control capabilities. In the course of its operations, KEYMARBLE has been reported to harvest stolen credentials, capture keystrokes, and download additional malicious payloads from command‑and‑control (C2) servers hosted in countries affiliated with adversarial actors. These actions enable long‑term intelligence gathering against high‑value targets such as diplomatic personnel or critical infrastructure operators. The impact of an infection can be severe: compromised systems may provide the attackers with a backdoor to access classified documents, insider threat insights, and potential sabotage vectors. Because the malware has been linked to a state‑backed actor, incidents are expected to exhibit a high level of persistence and sophistication, warranting rigorous monitoring and response. ---
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Data regarding KEYMARBLE is limited to a single attribution report. While the core description (trojan used by North Korean actors) is solid, technical capabilities are inferred from common behaviors of similar malware families and may not reflect actual implementation. Further samples or behavioral analysis would improve confidence.
KEYMARBLE is a Trojan that has reportedly been used by the North Korean government. (Citation: US-CERT KEYMARBLE Aug 2018)