All threat actors

TINKYWINKEY

Alert me

A Windows keylogger first publicly observed in 2025. It establishes service-based persistence and uses process injection to capture keystrokes and related user activity; it is a malware family rather than an attributed actor.

Create a free account to see the reports

Sign in or create a free account to see every report that names TINKYWINKEY.

Create free account