KerrDown is a custom Windows downloader malware family attributed to OceanLotus (APT32) and described as used exclusively by that group. Reporting in the provided content states it has been actively used since at least early 2018, primarily against Vietnam-based or Vietnamese-speaking targets, including in a spyware campaign targeting Vietnamese human rights defenders and the organization VOICE between 2018 and 2020. KerrDown is delivered through phishing emails either as malicious attachments or malicious links, and execution occurs when victims open the malicious file or link. Observed delivery chains include Microsoft Office lure documents with malicious macros and RAR archives that abuse DLL side-loading with a legitimate Microsoft Word 2007 executable loading a malicious wwlib.dll. The malware can also open a decoy document to appear benign.
Functionally, KerrDown acts as a downloader that installs additional spyware from attacker-controlled servers. In one documented macro-based variant, the lure document contains hidden base64 blobs, selects a 32-bit or 64-bit payload based on OS architecture, uses a VBS base64 decoder function published by Motobit, and drops a DLL disguised as main_background.png under Users\Administrator\AppData\Roaming. It then retrieves an encrypted payload from a remote URL, decrypts it with DES, and executes it in memory without writing the final payload to disk. Documented URLs include https://syn.servebbs[.]com/kuss32.gif for 32-bit systems and https://syn.servebbs[.]com/kuss64.gif for 64-bit systems. In a DLL side-loading variant, staged shellcode uses compression and encryption, including UCL decompression and AES decryption, retrieves additional shellcode from https://cortanasyn[.]com/Avcv, and ultimately loads an embedded Cobalt Strike Beacon in memory. The content also notes KerrDown-related infrastructure including syn[.]servebbs[.]com, cortanasyn[.]com, cortanazone[.]com, and a Beacon sample connecting to https://b.cortanazone[.]com.
The final payload observed in the provided reporting was a variant of Cobalt Strike Beacon. In the Amnesty-documented Windows infections, KerrDown downloaded Cobalt Strike onto victim systems, after which attackers could gain extensive access. High-confidence indicators mentioned in the content include SHA-256 89e19df797481ae2d2c895bcf030fe19e581976d2aef90c89bd6b3408579bfc3 for a malicious lure document and SHA-256 040abac56542a2e0f384adf37c8f95b2b6e6ce3a0ff969e3c1d572e6b4053ff3 for a RAR archive sample named "Don khieu nai.rar" ("Complaint letter").
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Windows spyware was a variant of a malware family called Kerrdown and used exclusively by the Ocean Lotus group. Kerrdown is a downloader that installs additional spyware from a server on the victim’s system and opens a decoy document.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using VBScript, VBS, VBA macros, and Visual Basic code for execution, payload delivery, persistence, reconnaissance, and command execution.
Once downloaded and launched on the victim’s computer, the spyware would then open a decoy document in line with what the email pretended to share to trick the victim in believing the file was benign.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
These emails pretended to share an important document... the spyware would then open a decoy document in line with what the email pretended to share to trick the victim in believing the file was benign.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
82 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Software changes: ... Kerrdown
A Windows malware family used exclusively by Ocean Lotus. It acts as a downloader, installing additional spyware from a server onto the victim system and opening a decoy document to disguise the infection.
Malware executed when victims open malicious files.
Custom downloader/loader used by OceanLotus (APT32) that is delivered via malicious Office macros or via DLL sideloading from RAR archives. It drops a DLL disguised as an image (e.g., main_background.png), downloads an encrypted payload from attacker-controlled URLs, decrypts it (DES noted), and executes it in-memory. A multi-stage variant uses base64 decoding, UCL decompression, AES decryption, remote stage retrieval, and ultimately loads an embedded Cobalt Strike Beacon DLL in memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.