KGH_SPY
S0526 · Windows
KGH_SPY is a modular suite of tools used by Kimsuky for reconnaissance, information stealing, and backdoor capabilities. KGH_SPY derived its name from PDB paths and internal names found in samples containing "KGH".
ATT&CK S0526
Sigma rules0
YARA rules0
Live IOCs0