Unknown Logger
MITRE ATT&CK: S0130 View on attack.mitre.org
Aliases: Unknown Logger
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:48:08
Context
Unknown Logger is a publicly released, free backdoor. Version 1.5 of the backdoor has been used by the actors responsible for the MONSOON campaign.
Detection coverage
- 305 Sigma rules
Malware & tools used
- System Owner/User Discovery (attack-pattern)
- Replication Through Removable Media (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Keylogging (attack-pattern)
- System Information Discovery (attack-pattern)
Used by threat actors
- Patchwork (threat-actor)
Reports & references
- forcepoint.com — Forcepoint Security Labs Monsoon Analysis Report (report)
- MITRE ATT&CK — S0130 (report)