KerrDown is a custom Windows downloader used by OceanLotus, also known as APT32 or APT-C-00, and associated with BISMUTH cyberespionage activity. It has been used since at least early 2018 to install additional malware, notably Cobalt Strike Beacon. Documented deployments include attacks against Vietnamese human rights defenders and organizations, as well as BISMUTH campaigns targeting private-sector and government institutions in France and Vietnam.
KerrDown is commonly implemented as a malicious Windows DLL and delivered through phishing or spearphishing emails containing malicious attachments or download links. Infection relies on victims opening malicious files, including archives containing legitimate applications paired with malicious DLLs. Execution chains abuse DLL side-loading through legitimate Microsoft Word 2007 or Opera executables. Decoy documents help conceal the infection, and scheduled tasks have been used to repeatedly launch a Word-based side-loading chain for persistence.
The malware decodes, decrypts, and decompresses multiple layers of shellcode, transferring execution between stages before downloading an additional payload or executing an embedded Cobalt Strike Beacon. Some variants use binary padding to hinder detection. KerrDown also shares code-level similarities with the OceanLotus Java-based tool JEShell, which similarly processes layered shellcode to deploy Cobalt Strike.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"wwlib.dll was a copy of KerrDown, a family of custom malware exclusive to BISMUTH."
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious document added a scheduled task that launched the MsMpEng.exe copy and sideloaded the malicious MpSvc.dll; another task launched malicious Word 2007 every 60 minutes.
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... has required user execution of a malicious MSI installer... has been executed through user installation of an executable disguised as a flash installer.
This malware uses custom base64 and AES algorithms to obfuscate all the strings, making it harder to analyse or build signatures
Expanding payloads with junk data is a technique, called “binary padding”, often used by malware to avoid detection
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
These emails pretended to share an important document... the spyware would then open a decoy document in line with what the email pretended to share to trick the victim in believing the file was benign.
Kerrdown is a dropper that uses several layers of shellcode to obfuscate the final payload. Each one of them decrypting and redirecting to the next layer
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Examples in the content include 'DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules,' 'Molerats decompresses ZIP files once on the victim machine,' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
95 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses a VBS Base64 decoder function as part of its operation.
Software changes: ... Kerrdown
Malware that decodes, decrypts, and decompresses multilayer shellcode.
Malware executed when victims open malicious files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.