KdcSponge is a credential-stealing malware tool associated with APT27 activity, particularly intrusions exploiting Zoho ManageEngine ADSelfService Plus in 2021. It is designed to target undocumented APIs in Microsoft’s implementation of Kerberos, enabling theft of authentication material from compromised Windows environments. KdcSponge has been observed alongside other post-exploitation tooling including Godzilla web shells and the NGLite trojan, indicating its role in follow-on credential access after initial compromise of internet-facing enterprise software. Its use has been linked to espionage-oriented operations affecting sectors such as healthcare, defense, energy, technology, education, consulting, and IT. KdcSponge is best characterized as a specialized credential theft utility used in targeted intrusions rather than a broad self-propagating malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In 2021, APT27 targeted multiple industries... by exploiting REST API authentication bypass in Zoho ManageEngine ADSelfService Plus (CVE-2021-40539), resulting in the compromise of at least nine organizations worldwide. Operators scanned vulnerable ADSelfService Plus servers... then delivered Godzilla web shells, the NGLite trojan, and the KdcSponge information stealer. | Operators scanned vulnerable ADSelfService Plus servers ... then delivered Godzilla web shells, the NGLite trojan, and the KdcSponge information stealer.
Operators scanned vulnerable ADSelfService Plus servers ... then delivered Godzilla web shells, the NGLite trojan, and the KdcSponge information stealer.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Operators scanned vulnerable ADSelfService Plus servers ... then delivered Godzilla web shells, the NGLite trojan, and the KdcSponge information stealer.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
APT27 gains initial access through a range of well-documented and opportunistic methods. The group has consistently exploited vulnerabilities in internet-facing applications, including high-profile cases like Zoho ManageEngine ADSelfService Plus (CVE-2021-40539) and Microsoft Exchange ProxyLogon/ProxyShell (CVE-2021-26855/-26857/-26858/-27065). They also targeted Apache Tomcat servers using Log4j vulnerabilities (CVE-2021-44228 and CVE-2021-45105).
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer used by APT27 in Zoho ManageEngine exploitation activity.
A named stealer referenced as part of related ManageEngine ADSelfService Plus attack reporting; this content does not provide additional technical details.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.