Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 8, 2026
- Feed role
- C2
- Host form
- 0 IP / 12 hostnames
KPOT Stealer is a Windows information-stealing malware family sold in cybercrime markets and used in criminal delivery campaigns since at least 2018.
Profile source: Mallory opens in a new tabKPOT Stealer
KPOT Stealer is a Windows information-stealing malware family sold in cybercrime markets and used in criminal delivery campaigns since at least 2018. It is designed to collect and exfiltrate credentials, cookies, autofill data, account information, and other sensitive artifacts from a broad set of applications, including web browsers, instant messengers, email clients, VPN software, remote access tools, FTP clients, cryptocurrency wallets, and gaming platforms. Documented targets include Chrome, Firefox, Internet Explorer, Outlook, Skype, Telegram, Discord, Steam, Battle.net, WinSCP, FileZilla, RDP-related data, Windows credentials, and multiple cryptocurrency applications and wallets.
Technically, KPOT is written in C/C++ and commonly employs packed samples, encrypted strings, and runtime API resolution to hinder analysis. Important strings are stored in encrypted form and decrypted with XOR-based routines at runtime. The malware resolves Windows APIs dynamically by parsing the PEB and hashing export names with a Murmur3-based algorithm, avoiding straightforward static imports. It communicates with command-and-control infrastructure over HTTP, retrieves tasking and configuration data, and exfiltrates collected results in encrypted form. Observed tasking includes theft of browser and application data, screenshot capture, collection of host profiling information, and file theft based on server-supplied grabber rules. Some analyzed variants also perform a geographic check and terminate on systems located in CIS countries.
Observed delivery has included email campaigns, exploit-kit activity, and malicious software download chains. One documented infection chain used a malicious RTF attachment exploiting CVE-2017-11882 to stage a downloader and ultimately deploy KPOT. The malware has also been distributed through compromised websites that replaced legitimate software downloads with trojanized installers. TA578 has been observed delivering KPOT in email-based campaigns alongside other crimeware families. In analyzed cases, some samples lacked a persistence mechanism and instead executed assigned tasks, posted results, and exited.
C2 tracking
Derp observations, rolling seven-day window
Samples
03fa9b41e1c76eac0a28f19eec5a4be419339da4dd7e8fcfae1712ec2d9de37b 43e0401ce84690fcd5a62d08ba2f0e60319a10e8f02bb15d7cde681c0a25f4a5 58ae4e54daa6c815ee1b3b8a52145dbc9dc33cfaa68f1ca43b492265e91d720d 6613ab9c70ac1a42ed9186b53038cf81d17f23e64ce50fc361427a08e17d4554 682eba88bd06c24afec3f95b4d0245ae14c6826fcba73ed48719a2462fb71f69 6c0e9a0493dfd84b3e94107bb5fb1b90d703fd9b118ec543ce52a5a79150c358 705e44b4c1aaa49b9acf5de18fce071d59d3b120d5d6a42b003b9eb22a2f6a48 760897cdaa6cdce9680aefe9917a2608c52b1d3ca696eac1e048a7955721345e 77b788d588146238fc0b896f4222ccc9b04fac42a5077b9b5da2598f60f2b241 9875973b5c0a9a974b76fa117e0df17660766df7710b5668f56730b4d95bca00 Reported operators
TA578 since May 2020 and uses email campaigns to deliver malware like Ursnif, IcedID, KPOT Stealer, Buer Loader, and BazaLoader
Exploited software
MITRE ATT&CK
Reporting
Researchers detailed KPOT v2.0, a commercially sold information-stealing malware strain designed to harvest credentials and sensitive data from browsers, messaging applications, email clients, VPN and RDP software, FTP clients, gaming platforms, and cryptocurrency wallets including Jaxx. The malware was marketed on underground forums at a low price point, making it accessible to a broad range of threat actors, and its targeting of wallet users highlighted the growing overlap between credential theft and cryptocurrency-focused crime. Observed delivery methods included email campaigns and exploit kits, including an RTF lure exploiting CVE-2017-11882 to launch a PowerShell-based loader that retrieved the final payload. Once executed, KPOT used encrypted strings, runtime API resolution, and an encrypted HTTP command-and-control configuration to receive tasks, exfiltrate system and credential data, and steal files matching attacker-defined rules. The analyzed variant notably used in-memory execution and no persistence, terminating after completing assigned tasks, and also checked for victims in CIS countries before exiting without infecting them.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.