PRIVATELOG
- First seen
- 2021-07-01 00:00:00
- Malware type
- loader
- Profile updated
- 2026-07-07 15:16:18
Context
Malware that abuses the Common Log File System (CLFS) to store/hide a second stage payload via registry transaction files.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Privatelog (report)
- twitter.com — 1433819369784610828 (report)
- cybereason.com — Operation Cuckoobees Deep Dive Into Stealthy Winnti Techniques (report)
- Mandiant — Unknown Actor Using Clfs Log Files For Stealth (report)
- cybereason.com — Operation Cuckoobees A Winnti Malware Arsenal Deep Dive (report)