winlog

First seen
2022-07-15 00:00:00
Malware type
credential-stealer
Profile updated
2026-07-07 15:26:25

Targeted industries: government-and-public-sector financial-services

Context

Winlog is a credential-stealing malware particularly used in targeted attacks against government and financial sectors. Its operations focus on harvesting user credentials and are often linked to state-sponsored cyber espionage campaigns.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Winlog (report)
  • github.com — Keylogger Windows Winlog (report)

External references