Last seven days
- First activity
- Aug 27, 2026
- Last activity
- Aug 27, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
KPOT Stealer is a Windows information-stealing malware family sold in cybercrime markets and used in criminal delivery campaigns since at least 2018.
Profile source: Mallory opens in a new tabKPOT Stealer
KPOT Stealer is a Windows information-stealing malware family sold in cybercrime markets and used in criminal delivery campaigns since at least 2018. It is designed to collect and exfiltrate credentials, cookies, autofill data, account information, and other sensitive artifacts from a broad set of applications, including web browsers, instant messengers, email clients, VPN software, remote access tools, FTP clients, cryptocurrency wallets, and gaming platforms. Documented targets include Chrome, Firefox, Internet Explorer, Outlook, Skype, Telegram, Discord, Steam, Battle.net, WinSCP, FileZilla, RDP-related data, Windows credentials, and multiple cryptocurrency applications and wallets.
Technically, KPOT is written in C/C++ and commonly employs packed samples, encrypted strings, and runtime API resolution to hinder analysis. Important strings are stored in encrypted form and decrypted with XOR-based routines at runtime. The malware resolves Windows APIs dynamically by parsing the PEB and hashing export names with a Murmur3-based algorithm, avoiding straightforward static imports. It communicates with command-and-control infrastructure over HTTP, retrieves tasking and configuration data, and exfiltrates collected results in encrypted form. Observed tasking includes theft of browser and application data, screenshot capture, collection of host profiling information, and file theft based on server-supplied grabber rules. Some analyzed variants also perform a geographic check and terminate on systems located in CIS countries.
Observed delivery has included email campaigns, exploit-kit activity, and malicious software download chains. One documented infection chain used a malicious RTF attachment exploiting CVE-2017-11882 to stage a downloader and ultimately deploy KPOT. The malware has also been distributed through compromised websites that replaced legitimate software downloads with trojanized installers. TA578 has been observed delivering KPOT in email-based campaigns alongside other crimeware families. In analyzed cases, some samples lacked a persistence mechanism and instead executed assigned tasks, posted results, and exited.
C2 tracking
Derp observations, rolling seven-day window
Samples
602e6bfee3ec35f5e5558c60ef505a7ce2264c5a2bde49d4d0b20113c353462d 658315611efdbd9e63c0e6c63d003de3ce9d2ac6c831789b67bc7d2b19cd7548 8cba5f47e8f4bc973ff52ed89f396d35b693acec82a4a3387a720432b0d3a702 a4cc973ac337531b429b6f4430c98fd227f879200df1afd21c9abcdcf9c9b786 d58ce24b9093d2cedcffaea6422589fb21283ed11907814e3e74e09cbfa4323e Reported operators
TA578 since May 2020 and uses email campaigns to deliver malware like Ursnif, IcedID, KPOT Stealer, Buer Loader, and BazaLoader
Exploited software
MITRE ATT&CK
Reporting
Researchers detailed KPOT v2.0, a commercially sold information-stealing malware strain designed to harvest credentials and sensitive data from browsers, messaging applications, email clients, VPN and RDP software, FTP clients, gaming platforms, and cryptocurrency wallets including Jaxx. The malware was marketed on underground forums at a low price point, making it accessible to a broad range of threat actors, and its targeting of wallet users highlighted the growing overlap between credential theft and cryptocurrency-focused crime. Observed delivery methods included email campaigns and exploit kits, including an RTF lure exploiting CVE-2017-11882 to launch a PowerShell-based loader that retrieved the final payload. Once executed, KPOT used encrypted strings, runtime API resolution, and an encrypted HTTP command-and-control configuration to receive tasks, exfiltrate system and credential data, and steal files matching attacker-defined rules. The analyzed variant notably used in-memory execution and no persistence, terminating after completing assigned tasks, and also checked for victims in CIS countries before exiting without infecting them.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.