Skip to main content
← Back to Demos
Malware intermediate · 15 min

Keylogger Keyboard Hook Detected by Behavioral Sandbox

Vidar infostealer campaigns currently target SMBs through malvertising and cracked-software downloads, with loaders inflated to hundreds of megabytes specifically to evade sandbox analysis. Stealers like Vidar depend on keylogging — installing a global keyboard hook to capture credentials as they are typed. This demo uses a benign test program that installs the same type of global hook, observing keystrokes only within the sandboxed environment. Adaptive Sandbox executes the sample and monitors Windows API calls, flagging the SetWindowsHookEx global-hook pattern as suspicious credential-harvesting behavior. A verdict and full behavioral timeline are produced without any real keylogger or malware ever being deployed.

Attack Technique

Keyboard hooking

MITRE ATT&CK

T1056.001 ↗

Platforms

linuxmacoswindows

File Types

.sh

MetaDefender Capabilities

Adaptive Sandbox

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---