Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 20:41:59 UTC Home > List all groups > List all tools > List all groups using tool PRIVATELOG Tool: PRIVATELOG Names PRIVATELOG Category Malware Type Loader Description (Cybereason) PRIVATELOG is a module that exists in 2 forms: • Wlbsctrl.dll: A DLL to be side-loaded by the IKEEXT service, aiming to execute on Windows Vista to Windows 7 operating systems. • Prntvpt.dll: A DLL to be side loaded by the PrintNotify service, aiming to execute on Windows Server 2012 to Windows 10 operating systems. As both of the DLLs are being loaded by native Windows services, they both live in the context of the svchost process, but differ in their execution flow. Information Malpedia Last change to this tool card: 27 December 2022 Download this tool card in JSON format All groups using tool PRIVATELOG Changed Name Country Observed APT groups   APT 41 2012-Jul 2025 1 group listed (1 APT, 0 other, 0 unknown) https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=3f25cda3-f293-4a3a-9b3a-7cdef172f7d9 Page 1 of 2 Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=3f25cda3-f293-4a3a-9b3a-7cdef172f7d9 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=3f25cda3-f293-4a3a-9b3a-7cdef172f7d9 Page 2 of 2 APT groups APT 41 2012-Jul 2025 1 group listed (1 APT, 0 other, 0 unknown) Page 1 of 2