[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/originlogger/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/originlogger/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# OriginLogger: A Look at Agent Tesla's Successor

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 14 min read  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Jeff White](https://unit42.paloaltonetworks.com/author/jeff-white/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:September 13, 2022

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [AgentTesla](https://unit42.paloaltonetworks.com/tag/agenttesla/)
  * [Analysis](https://unit42.paloaltonetworks.com/tag/analysis/)
  * [Keylogger](https://unit42.paloaltonetworks.com/tag/keylogger/)
  * [OriginLogger](https://unit42.paloaltonetworks.com/tag/originlogger/)
  * [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/originlogger/?pdf=download&lg=en&_wpnonce=fafa58d2d0 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/originlogger/?pdf=print&lg=en&_wpnonce=fafa58d2d0 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=OriginLogger:%20A%20Look%20at%20Agent%20Tesla’s%20Successor&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Foriginlogger%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Foriginlogger%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Foriginlogger%2F&title=OriginLogger:%20A%20Look%20at%20Agent%20Tesla’s%20Successor "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Foriginlogger%2F&text=OriginLogger:%20A%20Look%20at%20Agent%20Tesla’s%20Successor "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Foriginlogger%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=OriginLogger:%20A%20Look%20at%20Agent%20Tesla’s%20Successor%20https%3A%2F%2Funit42.paloaltonetworks.com%2Foriginlogger%2F "Share in Mastodon")

## **Executive Summary**

On March 4, 2019, one of the most well-known keyloggers used by criminals, called [Agent Tesla](https://unit42.paloaltonetworks.com/unit42-analyzing-various-layers-agentteslas-packing/), closed up shop due to legal troubles. In the announcement message posted on the Agent Tesla Discord server, the keylogger's developers suggested people switch over to a new keylogger: "If you want to see a powerful software like Agent Tesla, we would like to suggest you OriginLogger. OriginLogger is an AT-based software and has all the features." OriginLogger is a variant of Agent Tesla. As such, the majority of tools and detections for Agent Tesla will still trigger on OriginLogger samples.

Recently, when sitting down to analyze some malware tagged as Agent Tesla, I was surprised to learn I was actually looking at something else. This fact revealed itself to me when I began analyzing the malware families' configurations at scale after creating tooling to extract them.

In this blog, I will cover the OriginLogger keylogger malware, how it handles the string obfuscation for configuration variables and what I found when looking at the extracted configurations that allowed for better identification and further pivoting.

Palo Alto Networks customers receive protections from both OriginLogger and its predecessor malware Agent Tesla through [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and the [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with [cloud-delivered security services](https://www.paloaltonetworks.com/network-security/security-subscriptions) including [WildFire](https://www.paloaltonetworks.com/network-security/wildfire) and [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention).

|------------------------|--------------------------------------------------------------------|
| Related Unit 42 Topics | [Agent Tesla](https://unit42.paloaltonetworks.com/tag/agenttesla/) |

## **OriginLogger Builder**

When I began researching OriginLogger, I could find little to no public information about it. There are several Agent Tesla-related analysis blogs that I now recognize as pertaining to OriginLogger -- sometimes tagged as "AgentTeslav3" -- but otherwise, the public internet is pretty light on relevant information.

During my search, I stumbled across a [YouTube video](https://www.youtube.com/watch?v=o-MDujYrtto) posted in 2018 (before Agent Tesla closed up shop) by a person selling "fully undetectable" (FUD) tools. This person showed off the OriginLogger tools with a link to buy it from a known site that traffics in malware, exploits and the like.
![OriginLogger feature highlights include: Powerful keyboard hook (detects all keybaord strokes. It does not work with the timer, it hook directly. Origin Logger has support all languages (Chinese, Greek, Latins Etc.); Web Panel (You can monitoring your logs on your hosting. We are providing our panel scripts and we can help you for installation); colored Log (Origin Logger saves logs in HTML colored texts make reading easier); Smart Logger (with this feature, the keylogger starts to work only in the windows where the words you specify are detected).](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-25.png) Figure 1. OriginLogger feature highlights (Source: screenshots of the OriginLogger sale page from a YouTube video on OriginLogger). ![Full OriginLogger feature list includes the following: multilanguage support, 3 different delivery: PHP, SMTP and FTP, keylogger, colored log, screenshot logger, multi file binder, clipboard logger, smartlogger, password recovery, web panel, 7/24 support, fake message, autobuy, stable and fast, pure code, all windows OS supported, UAC bypass: WIN 7/8/10, assembly \& icon option](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-26.png) Figure 2. OriginLogger feature list.

Additionally, they showed both the web panel and the malware builder.
![Screenshot of the Origin Logger web panel, with the "keystrokes" option selected. The panel shows where you can view and delete logs and includes info on Server Time, HWID, Machine Name, Log, IP Address. It offers actions including view/delete, copy, CSV, Excel, PDF and Print](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-27.png) Figure 3. OriginLogger web panel (Source: OriginLogger YouTube video). ![OriginLogger builder. The screenshot shots selections including Keyboard Logger (time), Clipboard Logger, Delete Backspaces, Smart Logger (which allows the user to input specific words such as facebook, twitter, gmail, etc.), Screenshot Logger (time)](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-28.png) Figure 4. OriginLogger builder.

The image of the builder shown in Figure 4 was particularly interesting to me as it provided a default string -- facebook, twitter, gmail, instagram, movie, skype, porn, hack, whatsapp, discord -- that might be unique to this application. Sure enough, a content search on VirusTotal shows one matching file (SHA256: [595a7ea981a3948c4f387a5a6af54a70a41dd604685c72cbd2a55880c2b702ed](https://www.virustotal.com/gui/file/595a7ea981a3948c4f387a5a6af54a70a41dd604685c72cbd2a55880c2b702ed)) uploaded on May 17, 2022.
![Searching on VirusTotal for the string "facebook, twitter, gmail, instagram, movie, skype, porn, hack, whatsapp, discord" leads to the file SHA256: 595a7ea981a3948c4f387a5a6af54a70a41dd604685c72cbd2a55880c2b702ed as shown](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-29.png) Figure 5. VirusTotal search for string.

Downloading and attempting to run this file resulted in errors due to missing dependencies; however, knowing the builder's filename, OriginLogger.exe, allowed me to expand the search and locate a Zip archive (SHA256: [b22a0dd33d957f6da3f1cd9687b9b00d0ff2bdf02d28356c1462f3dbfb8708dd](https://www.virustotal.com/gui/file/b22a0dd33d957f6da3f1cd9687b9b00d0ff2bdf02d28356c1462f3dbfb8708dd)) containing all of the files required to run OriginLogger.
![bundled files in the Zip archive include OriginLogger.exe, Updater.exe, NetCore.dll, Mono.Cecil.dll, settings.ini, eula.html, profile.origin](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-30.png) Figure 6. Bundled files in Zip archive.

The settings.ini file contains the configuration the builder will use, and in Figure 7 we can see the previous search string listed under SmartWords.
![Settings.ini in OriginLogger includes logsettings such as Delivery, remember, keylogger, grabip, Log, ScreenLogger, screeninterval, Clipboard, Backspace, email, toemail, password, smtp, port, SSL, attach, ftphost, ftpuser, ftppassword, URL, UrlKey, istor, telegram\_api, telegram\_chatid, SmartLogger, SmartWords, smartLoggerType](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-31.png) Figure 7. OriginLogger Builder settings.ini file.

The file profile.origin contains the embedded username/password that a customer registers with when purchasing OriginLogger.
![Screenshot of the OriginLogger builder login screen, including fields for email and password and option to remember password.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-32.png) Figure 8. OriginLogger builder login screen.

Amusingly, if you flip around the values in the profile file, the plaintext password is revealed.
![Red arrows indicate which two values can be swapped in the profile.origin file to reveal the plaintext password.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-33.png) Figure 9. Contents of profile.origin file. ![Screenshot of the OriginLogger builder login screen, showing the results of flipping values in the file as shown in Figure 9. The threat actor's password is revealed in plaintext in the e-mail field, while the email is obfuscated in the password field.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-34.png) Figure 10. OriginLogger builder login screen with threat actor password revealed in plaintext.

When a user logs in, the builder attempts to authenticate with the OriginLogger servers to validate the subscription.

At this point, I had two versions of the builder. The first one (b22a0d\*), contained in the Zip file, was compiled Sept. 6, 2020. The other, which contained the SmartWords string (595a7e\*), was compiled on June 29, 2022, just about two years after the first.

The later version makes its authentication request over TCP/3345 to IP 23.106.223\[.\]46. Since March 3, 2022, this IP has resolved to the domain originpro\[.\]me. This domain has resolved to the following IP addresses:

23\.106.223\[.\]46  
204\.16.247\[.\]26  
31\.170.160\[.\]61

The second IP, 204.16.247\[.\]26, stands out due to resolving these other OriginLogger related domains:

originproducts\[.\]xyz  
origindproducts\[.\]pw  
originlogger\[.\]com

Things get more interesting when looking at the older builder. This one attempts to reach out to a different IP address for the authentication.

![The older version of OriginLogger reaches out to 74.118.138\[.\]76 for authentication as shown in the pcap](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-35.png) Figure 11. PCAP showing remote IP address. Unlike the IP addresses associated with originpro\[.\]me, 74.118.138\[.\]76 does not resolve to any OriginLogger domains directly but instead resolves to 0xfd3\[.\]com. Pivoting on this domain shows it contains both DNS MX and TXT records for mail.originlogger\[.\]com.

Beginning around March 7, 2022, the domain in question began resolving to IP 23.106.223\[.\]47, which is one value higher in the last octet than the IP used for originpro\[.\]me, which used 46.

These two IP addresses have shared multiple SSL certificates:

|-------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------|
| SHA1                                                                                                                                            | Serial Number                                                                                                                                         | Common Name                                                                                                | IPs Observed                                                            |
| [2dec9fdf91c3965960fecb28237b911a57a543e2](https://community.riskiq.com/search/certificate/sha1?query=2dec9fdf91c3965960fecb28237b911a57a543e2) | [38041735159378560318847695768150611562](https://community.riskiq.com/search/certificate/serialNumber?query=38041735159378560318847695768150611562)   | [WIN-4K804V6ADVQ](https://community.riskiq.com/search/certificate/subjectCommonName?query=WIN-4K804V6ADVQ) | 23.106.223\[.\]46 23.106.223\[.\]47                                     |
| [7a7e732229287c1d53a360e08201616179217117](https://community.riskiq.com/search/certificate/sha1?query=7a7e732229287c1d53a360e08201616179217117) | [133152806647474295963986900899009859692](https://community.riskiq.com/search/certificate/serialNumber?query=133152806647474295963986900899009859692) | [WIN-4K804V6ADVQ](https://community.riskiq.com/search/certificate/subjectCommonName?query=WIN-4K804V6ADVQ) | 23.106.223\[.\]46 23.106.223\[.\]47 74.118.138\[.\]76 204.16.247\[.\]26 |
| [3b3cf8039b779d93677273e09961203ffaac2d6f](https://community.riskiq.com/search/certificate/sha1?query=3b3cf8039b779d93677273e09961203ffaac2d6f) | [89480234209393487842197137895395039274](https://community.riskiq.com/search/certificate/serialNumber?query=89480234209393487842197137895395039274)   | [WIN-4K804V6ADVQ](https://community.riskiq.com/search/certificate/subjectCommonName?query=WIN-4K804V6ADVQ) | 23.106.223\[.\]46 23.106.223\[.\]47 74.118.138\[.\]76 204.16.247\[.\]26 |

*Table 1. Shared SSL certificates.*

The RDP login screens for both of the servers beginning with IP 23.106.223.X show a Windows Server 2012 R2 server with multiple accounts.

![RDP login screen for 23.106.223\[.\]46 shows a Windows Server 2012 R2 server with multiple accounts - administrator, ftpuser and postgres](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-36.png) Figure 12. RDP login screen for 23.106.223\[.\]46. When further searching for this domain, I came across the GitHub profile for user 0xfd3, which contains the two repositories shown in Figure 13.

![The two GitHub repositories associated with user 0xfd shown in the screenshot are OutlookPasswordRecovery and Chrome-Password-Recovery](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-37.png) Figure 13. User 0xfd GitHub.

I'll circle back to these later in the blog when looking at the code, but (spoiler alert) they are also used in OriginLogger.

## **Dropper Lure**

Before diving into the malware, I'll quickly cover the dropper that led to the sample I set out to analyze. As both Agent Tesla and OriginLogger are commercialized keyloggers, the initial droppers will vary greatly between campaigns and should not be considered unique to either. I present the below as a real-world example of an attack dropping OriginLogger and show that they can be quite convoluted and obfuscated.

The initial lure document is a Microsoft Word file (SHA256: [ccc8d5aa5d1a682c20b0806948bf06d1b5d11961887df70c8902d2146c6d1481](https://www.virustotal.com/gui/file/ccc8d5aa5d1a682c20b0806948bf06d1b5d11961887df70c8902d2146c6d1481)). When opened, this document displays a photo of a passport for a German citizen, along with a credit card. I'm not quite sure how enticing this would be as a lure for a normal user, but either way, you'll note the inclusion of numerous Excel Worksheets below the image, as shown in Figure 14.
![The Microsoft Word document displays a photo of a passport for a German citizen, along with a credit card. Numerous Excel worksheets appear below the image.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image.jpeg) Figure 14. Lure document.

Each of these sheets are contained in separate embedded Excel Workbooks and are exactly the same:

dc8b81e2f3ea59735eb1887128720dab292f73dfc3a96b5bc50824c1201d97cf Microsoft\_Excel\_97-2003\_Worksheet.xls  
dc8b81e2f3ea59735eb1887128720dab292f73dfc3a96b5bc50824c1201d97cf Microsoft\_Excel\_97-2003\_Worksheet1.xls  
dc8b81e2f3ea59735eb1887128720dab292f73dfc3a96b5bc50824c1201d97cf Microsoft\_Excel\_97-2003\_Worksheet10.xls  
dc8b81e2f3ea59735eb1887128720dab292f73dfc3a96b5bc50824c1201d97cf Microsoft\_Excel\_97-2003\_Worksheet2.xls  
dc8b81e2f3ea59735eb1887128720dab292f73dfc3a96b5bc50824c1201d97cf Microsoft\_Excel\_97-2003\_Worksheet3.xls  
dc8b81e2f3ea59735eb1887128720dab292f73dfc3a96b5bc50824c1201d97cf Microsoft\_Excel\_97-2003\_Worksheet4.xls  
dc8b81e2f3ea59735eb1887128720dab292f73dfc3a96b5bc50824c1201d97cf Microsoft\_Excel\_97-2003\_Worksheet5.xls  
dc8b81e2f3ea59735eb1887128720dab292f73dfc3a96b5bc50824c1201d97cf Microsoft\_Excel\_97-2003\_Worksheet6.xls  
dc8b81e2f3ea59735eb1887128720dab292f73dfc3a96b5bc50824c1201d97cf Microsoft\_Excel\_97-2003\_Worksheet7.xls  
dc8b81e2f3ea59735eb1887128720dab292f73dfc3a96b5bc50824c1201d97cf Microsoft\_Excel\_97-2003\_Worksheet8.xls  
dc8b81e2f3ea59735eb1887128720dab292f73dfc3a96b5bc50824c1201d97cf Microsoft\_Excel\_97-2003\_Worksheet9.xls

Within each Workbook is a singular macro that simply saves a command to execute at the following location:

C:\\Users\\Public\\olapappinuggerman.js
![Screenshot shows the macro contained within each Excel Workbook in the malicious Word document. This macro saves a command to execute at C:\\Users\\Public\\olapappinuggerman.js](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-38.png) Figure 15. Excel VBA macro.

Once run, this will download and execute via [MSHTA](https://attack.mitre.org/techniques/T1218/005/) the contents of the file at hxxp://www.asianexportglass\[.\]shop/p/25.html. A screenshot of the website is shown in Figure 16.

![A minimalist but legitimate-appearing website at hxxp://www.asianexportglass\[.\]shop](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-39.png) Figure 16. Website to appear legitimate. This file contains an embedded obfuscated script in the middle of the document as a comment.

![Hidden in a comment in the html of a legitimate-appearing website is an embedded obfuscated script.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-40.png) Figure 17. Website hidden comment.

Unescaping the script reveals the code shown in Figure 18, which downloads the next payload from a BitBucket snippet (hxxps://bitbucket\[.\]org/!api/2.0/snippets/12sds/pEEggp/8cb4e7aef7a46445b9885381da074c86ad0d01d6/files/snippet.txt) and establishes persistence with a scheduled task named calsaasdendersw that runs every 83 minutes and uses MSHTA again to execute the script contained within hxxp://www.coalminners\[.\]shop/p/25.html.
![The unescaped script shown downloads the next payload from a BitBucket snippet and establishes persistence with a scheduled task that runs every minutes and uses MSHTA to execute a script.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-41.png) Figure 18. Unescaped script.

The snippet hosted on the BitBucket website contains further obfuscated PowerShell code and two binaries encoded and compressed.

The first of the two files (SHA256: 23fcaad34d06f748452d04b003b78eb701c1ab9bf2dd5503cf75ac0387f4e4f8) is a C# reflective loader using [CSharp-RunPE](https://github.com/NYAN-x-CAT/CSharp-RunPE/blob/master/RunPE/RunPE.cs). This tool is used to hollow out a process and inject another executable inside of it; in this case, the keylogger payload will be placed inside the aspnet\_compiler.exe process.

![PowerShell command. The command shown begins with \[Reflection.Assembly\]](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-42.png) Figure 19. PowerShell command to execute method contained in dotNet assembly. Note the projFUD.PA class that the Execute method is called from. Morphisec released a blog in 2021 called "[Revealing the Snip3 Crypter, a highly evasive RAT loader](https://blog.morphisec.com/revealing-the-snip3-crypter-a-highly-evasive-rat-loader)," where they analyze a crypter-as-a-service and fingerprint the crypter's author using this artifact.

The second of the two files (SHA256: cddca3371378d545e5e4c032951db0e000e2dfc901b5a5e390679adc524e7d9c) is the OriginLogger payload.

## **OriginLogger Configuration**

As previously stated, the original intention of this analysis was to automate and extract configuration-related details from the keylogger. To achieve this, I started by looking at how the configuration-related strings are used.

I won't be diving into any of the actual functionality of the malware as it's fairly standard and mirrors analysis of older Agent Tesla variants. Just as the threat actors' advertisements state, the malware uses tried and true methods and includes the ability to keylog, steal credentials, take screenshots, download additional payloads, upload your data in a myriad of ways and attempt to avoid detection.

To start extracting configuration-related details, I needed to figure out how the user-supplied data is stored in the malware; it turned out to be straightforward. The builder will take the dynamic string values and concatenate them into a giant blob of text which is then encoded and stored in a byte array to be decoded at runtime. Once the malware runs and hits a particular function that needs a string, such as the HTTP address to upload screenshots to, it will pass the offset and string length to a function that will then carve out the text at that location within the blob.

To illustrate, below you can see the decoding logic used for the main blob of text.
![The decoding logic used for OriginLogger's main blob of text.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-43.png) Figure 20. OriginLogger plaintext blob decoding.

Each byte is XOR'd by the index of the byte within the byte array, and again XOR'd by the value 170 to reveal the plaintext.

For each sample generated by the builder, this blob of text will differ depending on what's configured, so offsets and positioning will change. Looking at the raw text shown in Figure 21 is helpful, but without splicing it up, it becomes hard to determine where the boundaries end or begin.
![Raw plaintext blog used by OriginLogger to store user-supplied data.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-44.png) Figure 21. Plaintext blob.

It also does not help when it comes time to analyze the malware, as you won't be able to discern when or where something is used. To figure this next piece out, I needed to look at how OriginLogger handles the splicing.

Below you can see the function responsible for carving out the string, followed by the beginning of the individual methods containing the offset and length.
![The screenshot shows the function responsible for carving out the string, followed by the beginning of the individual methods containing the offset and length.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-45.png) Figure 22. OriginLogger string functions.

In this case, if the B() method is called at some point by the malware, it will pass 2, 2, 27 to the obfuscated nameless function at the top of the image. The first integer is used for the array index where the decoded string will be stored. The second (offset) and third (length) integers are then passed to the GetString function to obtain the text. For this particular entry, the resulting value -- \<font color="#00b1ba"\>\<b\>\[ -- is used during the creation of the HTML page it uploads to display the stolen data.

Knowing how the string parsing works, I could then automate the extraction of these strings. To start, it helps to look at the underlying intermediate language (IL) assembly instructions.
![The underlying OriginLogger IL assembly instructions reveal three ldc.i4.X instructions that create a framework that can then be used to match all of the corresponding functions in the binary for parsing](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-46.png) Figure 23. OriginLogger IL instructions for string function.

For each of these lookups, the structure of the function block will remain the same. At index 6-8 in Figure 23, you will see three ldc.i4.X instructions where X dictates an integer value that will be pushed onto the stack before calling the previously described splicing function. This overall structure creates a framework that can then be used to match all of the corresponding functions in the binary for parsing.

Leveraging this, I wrote a script to identify the encoded byte array, determine the XOR values and then splice up the decoded blob in the same fashion the malware uses it. With this, you can scroll through the decoded strings and look for things of interest. Once something is identified, knowing the offset and subsequent function name, you can pivot into the part of the malware that leverages them.
![Example of OriginLogger decoded strings. Includes Index, Offset, Count, etc.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-47.png) Figure 24. OriginLogger decoded strings.

From here, I started renaming the obfuscated methods to reflect their actual values, which made analysis easier on the eyes.
![Example of renaming obfuscated methods to reflect their actual values.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-48.png) Figure 25. OriginLogger FTP upload function.

It should be noted that the same string deobfuscation can be achieved by using [de4dot](https://github.com/de4dot/de4dot) and its dynamic string decryption feature by specifying the string types as delegate and identifying the tokens of interest. This works extremely well for single file analysis.

Recall that I mentioned in the [OriginLogger Builder](#post-124970-_t4ayo8qr0nc) section of this blog that I'd circle back to the GitHub repositories of the 0xfd3 user. Take a look in Figure 26 at the Chrome Password Recovery code uploaded in March 2020 after OriginLogger took Agent Tesla's prominence in the keylogger world.
![Code from user 0xfd3's "Chrome Password Recovery" GitHub repository. Methods include: Chrome, Opera, Yandex, 360 Browser, Comodo Dragon, CoolNovo, SRWare Iron, Torch Browser and Brave Browser.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-49.png) Figure 26. Chrome Password Recovery.

Compare Figure 26 to the code from the OriginLogger sample with renamed methods shown in Figure 27.
![OriginLogger code with renamed methods, including: Opera, Comodo Dragon, Chrome, 360 Browser, Yandex, SRWare Iron, Torch Browser, Brave Browser, Iridium Browser, CoolNovo, 7Star, Epic Privacy Browser, Amigo, CentBrowser, CocCoc, Chedot, Elements Browser, Kometa, Sleipnir 6, Citrio.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-50.png) Figure 27. OriginLogger Chrome password stealing function.

Look familiar? These types of similarities abound as OriginLogger has continued development where Agent Tesla left off.

## **Identifying OriginLogger Through Artifacts**

Using this tooling, I extracted 1,917 different configurations, which gives insight into the exfiltration methods used and allows for clustering of samples based on the underlying infrastructure.

This is where I began to understand that what I was looking at wasn't Agent Tesla but instead a different keylogger -- OriginLogger. Two particular exfiltration methods that both showed multiple references to "origin" in some fashion led me to connect the dots.

For example, one of the URLs configured for a sample to upload keylogger and screenshot data to was hxxps://agusanplantation\[.\]com/new/new/inc/7a5c36cee88e6b.php. This URL is no longer active so I started searching for historical information about it to understand what was on the receiving end of these HTTP POST requests. By plugging in the domain to [URLScan.io](https://urlscan.io/search/#agusanplantation.com), it showed login pages for the panel in the same directory but, more importantly, that the OriginLogger web panel (SHA256: c2a4cf56a675b913d8ee0cb2db3864d66990e940566f57cb97a9161bd262f271) was observed on this host at the time of scanning four months ago.

![URLScan.io results for the agusanplantation\[.\]com domain includes an observation of the OriginLogger web panel.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-51.png) Figure 28. URLScan.io scan history for domain. Similarly, one of the exfiltration methods is through Telegram bots. To utilize them, OriginLogger requires a Telegram bot token to be included so the malware can interact with it. This provides another unique opportunity to analyze the infrastructure in use. In this case, I can use the token to query Telegram with what equates to a whoami command and observe the names used by the bot creator. Below are a handful of examples showing relevant naming.

"id":2046248941,"is\_bot":true,"first\_name":"origin","username":"mailerdemon\_bot"  
"id":1731070785,"is\_bot":true,"first\_name":"@CodeOnce\_bot","username":"PWORIGIN\_bot"  
"id":1644755040,"is\_bot":true,"first\_name":"ORIGINLOGGER","username":"softypaulbot"  
"id":1620445910,"is\_bot":true,"first\_name":"ORIGINLOGS","username":"badboi450hbot"  
"id":2081699912,"is\_bot":true,"first\_name":"Zara","username":"Zaraoriginbot"  
"id":5054839999,"is\_bot":true,"first\_name":"Origin Poster","username":"origin\_post\_bot"

## **Malicious Infrastructure**

Like other keyloggers that are commercially sold, OriginLogger is used by a wide variety of people for various malicious purposes around the globe. In the past, I've written about taking a [deeper look at the victims of keyloggers](https://unit42.paloaltonetworks.com/keybase-threat-grows-despite-public-takedown-a-picture-is-worth-a-thousand-words/) and what analyzing their screenshots can reveal about the potential intentions of the attackers. In this blog post, I will summarize some observations of the data extracted from the corpus of OriginLogger samples I collected. Most samples had multiple exfiltration techniques configured and I'll cover each one below.

**SMTP** is still the primary mechanism used for exfiltrating data and was identified in 1,909 samples. This is most likely because:

* The traffic will blend in with normal user traffic better than other included protocols.It's relatively easy for attackers to obtain stolen e-mail accounts.
* E-mail providers usually offer a large amount of storage space.

There were 296 unique e-mail recipient addresses for the stolen data and 334 unique e-mail account credentials used to send them.

**FTP** was configured in 1,888 samples using 56 unique FTP servers and 79 unique FTP accounts, with multiple accounts logging to different directories, likely based on different campaigns. Across the accessible servers, which were limited to 11 of the 56, there are 442 unique victims, with some victims being logged hundreds of times.

**Web uploads to the OriginLogger panel** followed closely behind and were configured in 1,866 samples, uploading to 92 unique URLs. When analyzing these URLs, the PHP file used for the upload showed a pattern of alphanumeric characters in the filename, with a couple of additional patterns presenting themselves in the directory structure. Looking into the source code of the web panel as shown in Figure 29 shows that the PHP filename is an MD5 value of some random bytes and is placed in the /inc/ (incoming) directory.
![Source code for setup.php shows that the PHP filename is an MD5 value of some random bytes and is placed in the /inc/ directory.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-52.png) Figure 29. OriginLogger source code for setup.php.

Keep in mind that many keylogger purchasers may not have much technical experience and tend to use a "full service" vendor that creates everything for them so that all they are required to do is distribute the keylogger. I suspect this is a reason for a lot of the URIs having similar structures. For example, the structure http://\<ipaddress\>/\<name\>/inc/\<md5\>.php is repeated throughout, and the first level of the directory shows values unlikely to be generated automatically -- possibly account-related:

b0ss/inc  
rich/inc  
divine/inc  
ma2on/inc  
darl/inc  
jboy/inc  
newmoney/inc

Likewise, this directory structure changes the inc to mawa and prepends webpanel to the name:

webpanel-roth/mawa  
webpanel-qwerty/mawa  
webpanel-dawn/mawa  
webpanel-charles/mawa  
webpanel-muti/mawa  
webpanel-ghul/mawa  
webpanel-reza/mawa

For the last exfiltration method, we have **Telegram** identified in 1,732 samples with 181 unique Telegram bots receiving the stolen data. In addition to being able to issue a whoami for the bot, we're able to query for information related to the channels where stolen information was uploaded. The most prominent of the channels are below with the details currently in use:

|-------|-------------------------------------------------------------------|----------------------------------|-----------------------------------------|
| Count | Channel Bio                                                       | Owner                            | Bot Name                                |
| 41    | Invest in bitcoin now and attain financial freedom                | Alaa Ahmed                       | obomike\_bot                             |
| 25    | Free Cannabis                                                     | Cry\_ptoSand                      | sales3w7\_bot, oasisx\_bot, valiat073\_bot |
| 21    | Atrium Investment Ltd: We Help You ACHIEVE YOUR LIFE GOALS        | Doris E. Athey                   | Tino08Bot                               |
| 20    | Self Discipline, Consistency and humanity.                        | Lucas Grayson                    | Odion2023bot                            |
| 18    | Come Closer                                                       | Anthony Forbes                   | Anthonyforbes2023bot                    |
| 14    | Think it, Code It                                                 | CodeOnce DeSpartan               | PWORIGIN\_bot                            |
| 12    | Dream cha$er 4L                                                   | Lurgard da Great                 | johnwalkkerBot                          |
| 11    | coder..no system is safe.. Private crypt 100$..knowledge is power | ☠️The Devil☠️( do not disturb )) | Skiddoobot                              |
| 10    | PhD Engineering                                                   | Alexander Macbill                | swft\_bot                          |

*Table 2. Prominent Channels*

Finally, one feature that is not utilized very often is the ability for OriginLogger to download an additional payload after infecting the victim system. In the samples discussed here, only two were configured to download additional malware.

## **Conclusion**

OriginLogger, much like its parent Agent Tesla, is a commoditized keylogger that shares many overlapping similarities and code, but it's important to distinguish between the two for tracking and understanding. Commercial keyloggers have historically catered to less advanced attackers, but as illustrated in the initial lure document analyzed here, this does not make attackers any less capable of using multiple tools and services to obfuscate and make analysis more complicated. Commercial keyloggers should be treated with equal amounts of caution as would be used with any malware.

Luckily, in this instance, because of the similarities between the two aforementioned keyloggers, detections and protections carried over from one generation to the next -- albeit with slightly inaccurate signature naming.

Palo Alto Networks customers receive protections from both OriginLogger and its predecessor malware Agent Tesla through [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and the [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with [cloud-delivered security services](https://www.paloaltonetworks.com/network-security/security-subscriptions) including [WildFire](https://www.paloaltonetworks.com/network-security/wildfire) and [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention).
Back to top

### Tags

* [AgentTesla](https://unit42.paloaltonetworks.com/tag/agenttesla/ "AgentTesla")
* [Analysis](https://unit42.paloaltonetworks.com/tag/analysis/ "Analysis")
* [Keylogger](https://unit42.paloaltonetworks.com/tag/keylogger/ "Keylogger")
* [OriginLogger](https://unit42.paloaltonetworks.com/tag/originlogger/ "OriginLogger")
* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Credential Gathering From Third-Party Software](https://unit42.paloaltonetworks.com/credential-gathering-third-party-software/ "Credential Gathering From Third-Party Software")

### Table of Contents

* 

### Related Articles

* [Know Ourselves Before Knowing Our Enemies: Threat Intelligence at the Expense of Asset Management](https://unit42.paloaltonetworks.com/asset-management/ "article - table of contents")
* [Why Threat Intelligence: A Conversation With Unit 42 Interns](https://unit42.paloaltonetworks.com/threat-intelligence-interns/ "article - table of contents")
* [Uncovering .NET Malware Obfuscated by Encryption and Virtualization](https://unit42.paloaltonetworks.com/malware-obfuscation-techniques/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")  
  ![Pictorial representation of malware bypassing DNS and communicating directly to IP addresses. Futuristic digital cityscape with glowing blue and orange geometric structures, resembling skyscrapers.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 4, 2026 [#### Almost Half of Malware Samples Communicate Direct to IP](https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/)

* [Command and Control](https://unit42.paloaltonetworks.com/tag/command-and-control/ "Command and Control")

* [D2IP](https://unit42.paloaltonetworks.com/tag/d2ip/ "D2IP")

* [Exfiltration](https://unit42.paloaltonetworks.com/tag/exfiltration/ "exfiltration")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/ "Almost Half of Malware Samples Communicate Direct to IP")  
  ![Pictorial representation of passwordless authentication. East Asian woman examining data on multiple screens in a high-tech environment, surrounded by digital graphics and code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/07_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 3, 2026 [#### Pass the Passkey: A Novel Attack Surface in Passwordless Authentication](https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/)

* [Google authenticator](https://unit42.paloaltonetworks.com/tag/google-authenticator/ "google authenticator")

* [Google Chrome](https://unit42.paloaltonetworks.com/tag/google-chrome/ "Google Chrome")

* [Google Cloud](https://unit42.paloaltonetworks.com/tag/google-cloud/ "Google Cloud")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/ "Pass the Passkey: A Novel Attack Surface in Passwordless Authentication")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
