KiwiStealer is a Windows file-stealing malware family associated with the Bitter espionage group, also tracked as TA397. First observed in late 2024, it is designed for intelligence collection rather than broad criminal monetization. The malware gathers basic host identifiers such as username and computer name, traverses predefined directories, and searches for files matching a hardcoded set of document, archive, image, certificate, mobile application, and VPN-related extensions. Reported selection logic includes prioritizing files modified within the past year and excluding files larger than 50 MB. Before transmission, it records metadata about collected files, then exfiltrates the selected content to operator-controlled infrastructure.
KiwiStealer has been linked to Bitter’s broader espionage operations targeting a narrow set of victims, especially government, diplomatic, and defense-related organizations. Bitter commonly relies on spearphishing-led intrusion chains and follow-on operator activity, and KiwiStealer appears to function as a focused collection component within that ecosystem. Its behavior is consistent with targeted document theft and operational harvesting of potentially sensitive user files, credentials in certificate form, and configuration material relevant to access or intelligence objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer referenced as a malware used for file exfiltration (mentioned as a top blog topic).
Data stealer that searches for recently modified files (under 50MB) matching predefined extensions and exfiltrates them to a remote server.
A file stealer that gathers host/user information, traverses predefined directories, filters files by size and modification time, logs collected paths, and exfiltrates selected files to C2. It targets a broad set of document, archive, certificate, VPN, and other file types.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.