Skip to content

KPOT Stealer

KPOT Stealer is a Windows information-stealing malware family sold in cybercrime markets and used in criminal delivery campaigns since at least 2018.

Profile source: Mallory opens in a new tab

KPOT Stealer

Family profile

KPOT Stealer is a Windows information-stealing malware family sold in cybercrime markets and used in criminal delivery campaigns since at least 2018. It is designed to collect and exfiltrate credentials, cookies, autofill data, account information, and other sensitive artifacts from a broad set of applications, including web browsers, instant messengers, email clients, VPN software, remote access tools, FTP clients, cryptocurrency wallets, and gaming platforms. Documented targets include Chrome, Firefox, Internet Explorer, Outlook, Skype, Telegram, Discord, Steam, Battle.net, WinSCP, FileZilla, RDP-related data, Windows credentials, and multiple cryptocurrency applications and wallets.

Technically, KPOT is written in C/C++ and commonly employs packed samples, encrypted strings, and runtime API resolution to hinder analysis. Important strings are stored in encrypted form and decrypted with XOR-based routines at runtime. The malware resolves Windows APIs dynamically by parsing the PEB and hashing export names with a Murmur3-based algorithm, avoiding straightforward static imports. It communicates with command-and-control infrastructure over HTTP, retrieves tasking and configuration data, and exfiltrates collected results in encrypted form. Observed tasking includes theft of browser and application data, screenshot capture, collection of host profiling information, and file theft based on server-supplied grabber rules. Some analyzed variants also perform a geographic check and terminate on systems located in CIS countries.

Observed delivery has included email campaigns, exploit-kit activity, and malicious software download chains. One documented infection chain used a malicious RTF attachment exploiting CVE-2017-11882 to stage a downloader and ultimately deploy KPOT. The malware has also been distributed through compromised websites that replaced legitimate software downloads with trojanized installers. TA578 has been observed delivering KPOT in email-based campaigns alongside other crimeware families. In analyzed cases, some samples lacked a persistence mechanism and instead executed assigned tasks, posted results, and exited.

Capabilities

  • Credential Theft
  • Exfiltration
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 27, 2026
Last activity
Aug 27, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • DE1

Leading providers

  • Amazon.com, Inc.1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
TA578

TA578 since May 2020 and uses email campaigns to deliver malware like Ursnif, IcedID, KPOT Stealer, Buer Loader, and BazaLoader

Exploited software

Vulnerabilities linked to KPOT Stealer

1 CVEs

MITRE ATT&CK

KPOT Stealer in ATT&CK

25 distinct techniques

Reporting

Research mentioning KPOT Stealer

Dec 15
Github Web

Malware-analysis-and-Reverse-engineering/kpot2/KPOT.md at main · Dump-GUY/Malware-analysis-and-Reverse-engineering · GitHub

Researchers detailed KPOT v2.0, a commercially sold information-stealing malware strain designed to harvest credentials and sensitive data from browsers, messaging applications, email clients, VPN and RDP software, FTP clients, gaming platforms, and cryptocurrency wallets including Jaxx. The malware was marketed on underground forums at a low price point, making it accessible to a broad range of threat actors, and its targeting of wallet users highlighted the growing overlap between credential theft and cryptocurrency-focused crime. Observed delivery methods included email campaigns and exploit kits, including an RTF lure exploiting CVE-2017-11882 to launch a PowerShell-based loader that retrieved the final payload. Once executed, KPOT used encrypted strings, runtime API resolution, and an encrypted HTTP command-and-control configuration to receive tasks, exfiltrate system and credential data, and steal files matching attacker-defined rules. The analyzed variant notably used in-memory execution and no persistence, terminating after completing assigned tasks, and also checked for victims in CIS countries before exiting without infecting them.

Apr 12
Handlers Diary Full

Reader Analysis: "Dynamic analysis technique to get decrypted KPOT Malware."

May 9
Proofpoint Threat Insight

New KPOT v2.0 stealer brings zero persistence and in-memory features to silently steal credentials | Proofpoint US

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.