Keylogger Keyboard Hook Detected by Behavioral Sandbox
Vidar infostealer campaigns currently target SMBs through malvertising and cracked-software downloads, with loaders inflated to hundreds of megabytes specifically to evade sandbox analysis. Stealers like Vidar depend on keylogging — installing a global keyboard hook to capture credentials as they are typed. This demo uses a benign test program that installs the same type of global hook, observing keystrokes only within the sandboxed environment. Adaptive Sandbox executes the sample and monitors Windows API calls, flagging the SetWindowsHookEx global-hook pattern as suspicious credential-harvesting behavior. A verdict and full behavioral timeline are produced without any real keylogger or malware ever being deployed.
Attack Technique
Keyboard hooking
MITRE ATT&CK
T1056.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗