Kraken is an overloaded malware name that has referred to multiple distinct threats. The best-supported modern usage is a Golang-based Windows botnet first observed in 2021. That botnet spread via SmokeLoader, established persistence, evaded Microsoft Defender by adding exclusions, hid its executable, and supported downloading and executing secondary payloads, running shell commands, taking screenshots, and stealing cryptocurrency wallet data. Operators were observed primarily using it to deploy information stealers such as RedLine Stealer, and later also other stealers and cryptocurrency miners. Some builds briefly included SSH brute-force functionality, though reporting indicated it was quickly removed and not observed in operational use. Historically, Kraken has also referred to the older Bobax/Oderoor spam botnet, known for large-scale spam operations and use of a domain generation algorithm. Separately, in 2025, Kraken was used as the name of a ransomware operation linked to remnants of the HelloKitty ecosystem, conducting double-extortion and targeting Windows, Linux, and VMware ESXi with platform-specific encryptors. Because these are distinct malware lineages sharing the same name, attribution and classification should be handled carefully to avoid conflating the 2021 Windows botnet with the historical spam botnet or the later ransomware operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The source code also appears to have been merged into one main file with most of the function names being obfuscated, as opposed to the previously separated but clear functionality.
A new Golang-based botnet under active development has been ensnaring hundreds of Windows devices each time its operators deploy a new command and control (C2) server.
The code incorporates a timestamp, which is determined by making an HTTP request to a randomly picked, legitimate website. The date is extracted from the http date header of the response and converted to unix timestamp format.
Kraken has a limited and simplistic feature set, allowing attackers to download and execute additional malicious payloads on compromised devices, including the RedLine Stealer malware.
MITRE ATT&CK ID Description T1132.001 Data Encoding: Standard Encoding
For the first version, these base domains are four dynamic DNS providers... “dyndns.org” → “yi.org” → “dynserv.com” → “mooo.com”
139 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kraken ransomware is identified as a significant new player in the 2025 ransomware landscape, operating as a ransomware-as-a-service (RaaS) and contributing to the ongoing fragmentation and rapid evolution of ransomware families.
Low-volume ransomware brand referenced as part of the long-tail of operators.
Kraken is a ransomware-as-a-service (RaaS) operation that targets multiple platforms, including Windows, Linux, and VMware ESXi. It uses customized encryptors for each platform and is linked to the former HelloKitty ransomware group.
Ransomware associated with big-game hunting and double-extortion activity (noted by Talos in Aug 2025).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.