Kasidet is a Windows point-of-sale malware family associated with payment-card theft from POS environments and additional botnet-style functionality. It has been described as a POS memory scraper that harvests payment card data from infected systems and as malware that can also support distributed denial-of-service activity. Kasidet has been linked to command-and-control concealment through Namecoin Dot-Bit infrastructure and has been observed in broader malware-delivery ecosystems alongside other commodity malware families.
Documented capabilities attributed to Kasidet include process discovery, keylogging, screen capture, security software discovery, command execution through the Windows command shell, and persistence via Registry Run autoruns. It can search for specific running processes, identify installed antivirus products, log keystrokes, and capture the victim screen. Persistence has been reported through creation of Windows Run key entries.
Kasidet has been associated with multiple delivery vectors, including malicious websites, exploit-kit activity, spam and phishing campaigns, and macro-enabled Microsoft Office lures. It has also appeared as a payload dropped by signed or otherwise obfuscated crypter-based distribution chains. Reporting has associated Kasidet with Russian-linked activity, but attribution claims tying specific infections to state actors should be treated cautiously unless independently corroborated in a given case.
The malware primarily targets Windows systems, especially retail and payment-processing environments where POS card data is present in memory.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Kasidet POS Worm gets on a system along with the other malware or gets downloaded unknowingly when user visits malicious websites.
Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Then the scraped information is sent to the cyber criminal with intercepted GET and POST requests from the browser.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Only referenced as prior implant activity associated with IPs involved in the first attack.
Mentioned as another malware family dropped by the same crypter infrastructure observed in connection with iSpy.
Malware that establishes persistence by creating a Registry Run key.
Backdoor malware with keylogging and screen capture functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.