KL Gorki is a Brazilian banking malware lineage associated with financially motivated credential theft and online banking fraud. It is part of a long-running ecosystem of Brazil-focused banking trojans linked in reporting to the AllaKore and AllaSenha lineage, with later evolutions including CarnavalHeist and NFe-RAT. KL Gorki is best understood as an intermediate family or cluster within this broader lineage rather than an isolated intrusion set. Operations associated with this lineage target Brazilian users and financial institutions through phishing-driven initial access, followed by staged malware delivery and in-memory execution of Delphi-based banking trojans. Observed tradecraft in descendant campaigns includes abuse of Windows features for execution, multi-stage loaders using scripting and embedded runtimes, persistence via user-run startup mechanisms, reflective DLL injection, and anti-analysis or anti-response checks. Functional objectives include theft of banking credentials, keylogging, screen capture, remote control of infected systems, and fraud involving Brazil's PIX instant-payment ecosystem. The malware family has also used actions intended to disrupt remote assistance or incident response, indicating defense-evasion and post-exploitation capability. Known aliases and related lineage names include AllaKore, AllaSenha, CarnavalHeist, and NFe-RAT. High-confidence reporting places this activity in Brazil and indicates a primary focus on Brazilian victims, especially customers of multiple Brazilian banks. The dominant motivation is financial gain through banking fraud rather than espionage or destructive activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.