KerrDown is a Windows downloader malware family associated with OceanLotus, also tracked as APT32, and is widely described as tooling used exclusively by that threat actor. It has been used in targeted espionage operations, including campaigns against Vietnamese human rights defenders and organizations, and has also appeared in broader OceanLotus intrusion activity alongside related tooling such as JEShell and Cobalt Strike. KerrDown commonly serves as an intermediate payload that decodes and executes multiple layers of shellcode before downloading or installing a final implant, frequently a Cobalt Strike Beacon. Some variants also open decoy documents to reduce suspicion after execution.
Operationally, KerrDown is notable for layered unpacking and execution. Samples have been observed decoding, decrypting, and decompressing several shellcode stages, with each stage transferring execution to the next until the final payload is launched. It has also used DLL side-loading to gain execution through legitimate applications, including chains involving legitimate Microsoft Word components, and reporting describes KerrDown as a Windows DLL in some deployments. Additional tradecraft includes use of Visual Basic Script components such as a VBS Base64 decoder function.
Delivery has been tied to phishing activity, including malicious email attachments and emails containing malicious links, with execution often depending on victims opening weaponized files. In documented OceanLotus campaigns, Windows infection chains used archive-contained lure files and legitimate executables to side-load malicious DLLs that ultimately deployed KerrDown. The malware has been linked to espionage-focused targeting rather than indiscriminate crimeware distribution, with observed victims including civil society and human rights targets connected to Vietnam.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The final payload is always a variant of a downloader used exclusively by Ocean Lotus and named Kerrdown by the cybersecurity company Palo Alto. All the Kerrdown samples we analysed delivered a Cobalt Strike payload.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
This malware uses custom base64 and AES algorithms to obfuscate all the strings, making it harder to analyse or build signatures
Expanding payloads with junk data is a technique, called “binary padding”, often used by malware to avoid detection
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
These emails pretended to share an important document... the spyware would then open a decoy document in line with what the email pretended to share to trick the victim in believing the file was benign.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Examples in the content include 'DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules,' 'Molerats decompresses ZIP files once on the victim machine,' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
95 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses a VBS Base64 decoder function as part of its operation.
Software changes: ... Kerrdown
Malware that decodes, decrypts, and decompresses multilayer shellcode.
Malware executed when victims open malicious files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.