KPOT is a commercially distributed information-stealing malware family targeting Windows, first observed in 2018. It harvests passwords and sensitive user data from web browsers, email clients, instant messengers, VPN software, RDP services, FTP applications, gaming clients, and cryptocurrency and electronic-payment wallets. Its collection capabilities include browser cookies, Telegram session data, chat histories, and cryptocurrency-related files. KPOT profiles compromised systems and sends stolen information to attacker-controlled infrastructure.
KPOT has been delivered through phishing emails, malicious PowerShell downloaders, counterfeit software installers, and malvertising campaigns using the Fallout Exploit Kit. Buer Loader has deployed it alongside Amadey and Smoke Loader. In a 2020 campaign, a counterfeit WiseCleaner download site distributed an installer that executed KPOT before CoronaVirus ransomware. Other observed delivery chains used a legitimate AutoIt interpreter and an obfuscated script to decrypt KPOT in memory and execute it through process hollowing, avoiding writing the decrypted payload to disk. KPOT samples also use encoded strings to conceal command-and-control and collection-related information. In the CoronaVirus campaign, KPOT did not establish autorun persistence and deleted itself after execution.
KPOT was sold through Russian-speaking cybercrime communities as an off-the-shelf stealer. A REvil operator known as UNKN purchased the source code for KPOT 2.0 at an underground auction in 2020. This acquisition links the family to the ransomware ecosystem but does not establish that subsequent REvil tooling incorporated KPOT.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
New Actor for win.kpot_stealer ... rule win_kpot_stealer_auto ... description = "Detects win.kpot_stealer." ... rule win_kpot_stealer_w0 { meta: description = "Kpot" type = "Stealer"
26 distinct techniques documented for this family, organized by ATT&CK tactic.
...обманных загрузок, ботнетов, эксплойтов, вредоносной рекламы, веб-инжектов, фальшивых обновлений, перепакованных и заражённых инсталляторов.
hxxp://show1[.]website/OerAS.dat (Obfuscated AutoIt script, Base64 encoded as a certificate) ... Excerpt from Base64 decoded AutoIt script(‘i8ek7’) showing obfuscation
CoronaVirusランサムウェアは、「WiseCleaner」という(およびそれに付随する)正規アプリケーションを装った偽ダウンロードサイトから配布されている偽インストーラーを実行することで最終的に感染するランサムウェアです。
The AutoIt script contains process hollowing shellcode ... that decrypts the encrypted PE file as guest and uses 32-bit dllhost.exe as host
その後、自身を終了して削除します。Kpotはシステムに永続的に起動させるような自動起動エントリーは作成しない点から、使い捨ての情報窃取マルウェアとして使用されていることがわかります。
The PowerShell script uses certutil to BASE64-decode the "certificate" to the AutoIt script
Il est conçu pour collecter et exfiltrer des données sensibles présentes sur la machine compromise, notamment les identifiants enregistrés dans les navigateurs web, les cookies de session, les données de remplissage automatique, les informations relatives aux portefeuilles de cryptomonnaies ainsi que certains fichiers et paramètres système.
KPOT is a classic "information stealer" that can extract and steal passwords from various apps on infected computers. | This includes web browsers, instant messengers, email clients, VPNs, RDP services, FTP apps, cryptocurrency wallets, and gaming software.
337 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infostealer paired with CoronaVirus ransomware to harvest cryptocurrency wallets, browser data, and credentials.
Information stealer used in ransomware attacks.
An off-the-shelf stealer referenced through C2 infrastructure tied to the same operator or campaign artifacts.
Mentioned as an example of a retired malware family whose evolutions may be detected through reused code and configuration overlaps. Its capabilities and a direct relationship to Koi are not established in the excerpt.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.