KPOT is a Windows information-stealing malware family active since at least 2018 and commonly referred to as an infostealer trojan. It is designed to harvest credentials and other sensitive data from infected systems, including browser-stored passwords and cookies, email and messaging client data, VPN and RDP credentials, FTP credentials, Windows-stored secrets, cryptocurrency wallet-related data, gaming account data, and session material from selected applications. Reported behavior also includes host profiling and exfiltration of collected data to attacker-controlled infrastructure.
KPOT has appeared both as a standalone commodity stealer and as a component in broader criminal intrusion chains. It has been delivered through fake software installers, phishing-driven PowerShell downloaders, malvertising, and exploit-kit activity, and has also been observed as a secondary payload dropped by loaders such as Buer. In some campaigns it was deployed immediately before ransomware, suggesting credential theft and data collection were prioritized ahead of disruptive monetization. Delivery chains have included obfuscated scripts and in-memory execution, including AutoIt-assisted decryption and process hollowing into legitimate Windows processes to reduce on-disk visibility.
The malware is associated with cybercriminal use rather than a single exclusive operator. It has been sold as an off-the-shelf stealer in underground markets, bundled with supporting infrastructure services, and its source code was reportedly acquired by a REvil operator for further development. KPOT has also been cited as one of several stealers used in ransomware attack chains to provide access, credential material, and victim intelligence. The family targets Windows systems and is relevant across both consumer and enterprise environments because of its broad credential and wallet theft focus.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
New Actor for win.kpot_stealer ... rule win_kpot_stealer_auto ... description = "Detects win.kpot_stealer." ... rule win_kpot_stealer_w0 { meta: description = "Kpot" type = "Stealer"
26 distinct techniques documented for this family, organized by ATT&CK tactic.
...обманных загрузок, ботнетов, эксплойтов, вредоносной рекламы, веб-инжектов, фальшивых обновлений, перепакованных и заражённых инсталляторов.
hxxp://show1[.]website/OerAS.dat (Obfuscated AutoIt script, Base64 encoded as a certificate) ... Excerpt from Base64 decoded AutoIt script(‘i8ek7’) showing obfuscation
CoronaVirusランサムウェアは、「WiseCleaner」という(およびそれに付随する)正規アプリケーションを装った偽ダウンロードサイトから配布されている偽インストーラーを実行することで最終的に感染するランサムウェアです。
The AutoIt script contains process hollowing shellcode ... that decrypts the encrypted PE file as guest and uses 32-bit dllhost.exe as host
その後、自身を終了して削除します。Kpotはシステムに永続的に起動させるような自動起動エントリーは作成しない点から、使い捨ての情報窃取マルウェアとして使用されていることがわかります。
The PowerShell script uses certutil to BASE64-decode the "certificate" to the AutoIt script
Il est conçu pour collecter et exfiltrer des données sensibles présentes sur la machine compromise, notamment les identifiants enregistrés dans les navigateurs web, les cookies de session, les données de remplissage automatique, les informations relatives aux portefeuilles de cryptomonnaies ainsi que certains fichiers et paramètres système.
KPOT is a classic "information stealer" that can extract and steal passwords from various apps on infected computers. | This includes web browsers, instant messengers, email clients, VPNs, RDP services, FTP apps, cryptocurrency wallets, and gaming software.
337 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infostealer paired with CoronaVirus ransomware to harvest cryptocurrency wallets, browser data, and credentials.
Information stealer used in ransomware attacks.
An off-the-shelf stealer referenced through C2 infrastructure tied to the same operator or campaign artifacts.
Named malware/tool listed as detectable via SHA-256 hash in a compilation of attacker infrastructure and malware-related indicators.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.