Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-02 11:16:22 UTC Home > List all groups > List all tools > List all groups using tool kl.ps1 Tool: kl.ps1 Names kl.ps1 Category Malware Type Keylogger Description (SecureWorks) kl.ps1 is a custom keylogger that is written in PowerShell and leverages elements of the Microsoft .NET Core framework. It captures the window title and keystrokes on infected systems and stores them as Base64-encoded data. It is deployed using a scheduled task and a VBScript file. Figure 2 shows the command line used to run the keylogger script. Information Last change to this tool card: 20 April 2020 Download this tool card in JSON format All groups using tool kl.ps1 Changed Name Country Observed APT groups   Hexane 2017-Jun 2022   1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=eddbc3bf-640d-4af8-bfd3-d4c446adc0e5 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=eddbc3bf-640d-4af8-bfd3-d4c446adc0e5 Page 1 of 1