KOCTOPUS is a malware family or intrusion set tracked for using script obfuscation and security-control tampering to evade detection on compromised Windows systems. Observed tradecraft includes obfuscating scripts with the BatchEncryption tool, indicating a focus on concealing execution logic and hindering static or behavioral analysis. KOCTOPUS has also been associated with attempts to delete or disable Microsoft Security Defender and Security Essentials-related registry keys and scheduled tasks, reflecting deliberate defense-evasion activity aimed at weakening host protections prior to or during follow-on actions. Publicly supported information in this context is limited, and no high-confidence attribution to a nation-state, criminal ecosystem, or broader alias set is established here beyond the KOCTOPUS name itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Defense evasion by removing/neutralizing Defender/Security Essentials persistence and configuration via registry and scheduled task tampering.
Obfuscates scripts using BatchEncryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.