Unknown Logger

MITRE ATT&CK: S0130 View on attack.mitre.org

Aliases: Unknown Logger

Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:48:08

Context

Unknown Logger is a publicly released, free backdoor. Version 1.5 of the backdoor has been used by the actors responsible for the MONSOON campaign.

Detection coverage

  • 305 Sigma rules

Malware & tools used

  • System Owner/User Discovery (attack-pattern)
  • Replication Through Removable Media (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Keylogging (attack-pattern)
  • System Information Discovery (attack-pattern)

Used by threat actors

Reports & references

  • forcepoint.com — Forcepoint Security Labs Monsoon Analysis Report (report)
  • MITRE ATT&CK — S0130 (report)

External references