KOCTOPUS is a Windows malware family associated with socially engineered delivery and post-compromise execution through native scripting and system utilities. Reported behavior includes distribution through spearphishing emails carrying malicious attachments as well as malicious links, with lures themed to resemble legitimate software related to the travel and airline sectors. Execution has relied on user interaction, including opening or clicking malicious documents.
Once launched, KOCTOPUS uses VBScript and Windows Script Host to invoke PowerShell, including hidden-window execution to reduce user visibility. It has used PowerShell to download additional components, indicating staged delivery and follow-on payload retrieval. The malware also modifies and deletes Windows Registry data and has been observed attempting to disable or remove Microsoft Security Defender and Security Essentials-related registry keys and scheduled tasks, reflecting deliberate defense evasion.
KOCTOPUS can escalate privileges by bypassing User Account Control through techniques involving trusted Windows binaries such as fodhelper.exe and eventvwr.exe. It has also deployed a modified Invoke-Ngrok utility to expose local ports to the Internet, enabling remote access or tunneling from compromised hosts. Overall, KOCTOPUS exhibits a combination of phishing-based delivery, script-driven execution, privilege escalation, payload staging, registry tampering, and security-control impairment on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware being delivered through phishing or spearphishing emails containing malicious attachments such as Microsoft Office documents, PDFs, RAR/ZIP archives, CHM, ISO, IMG, HTA, LNK, and executable files disguised as documents.
Multiple actors and malware families are described as sending spearphishing/phishing emails containing malicious links (including shortened URLs, cloud-hosted links, and links to archives or documents) to deliver malware, harvest credentials, or redirect victims to malicious content.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions. | APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. Blue Mockingbird has used batch script files to automate execution and deployment of payloads. During HomeLand Justice, threat actors used Windows batch files for persistence and execution.
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
"ADVSTORESHELL is capable of starting a process using CreateProcess"; "build_downer has the ability to use the WinExec API"; "Aria-body has the ability to launch files using ShellExecute"
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Numerous malware families and threat groups are described as achieving persistence by adding values under Run/RunOnce/Policies\Explorer\Run Registry keys or by placing shortcuts/files in the Windows Startup folder.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
"Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "ADVSTORESHELL... strings... encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed." / "APT29 has used encoded PowerShell commands." / "APT41 used VMProtected binaries..."
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Bad Rabbit has masqueraded as a Flash Player installer through the executable file install_flash_player.exe.
Bisonal has deleted Registry keys to clean up its prior activity. FIN8 has deleted Registry keys during post compromise cleanup activities. SUNBURST also deleted previously-created Image File Execution Options (IFEO) Debugger registry values and registry keys related to HTTP proxy to clean up traces of its activity.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
The content repeatedly describes threat actors and malware disabling, stopping, uninstalling, or modifying antivirus, EDR, Windows Defender, AMSI, logging, and other security controls.
Examples include 'Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools', 'BlackByte disabled security tools such as Windows Defender', 'Scattered Spider has uninstalled and disabled security tools', and many malware families terminating AV/EDR processes or services.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that hides command windows using hidden window style parameters.
Uses VBScript and wscript to launch PowerShell commands.
Malware that uses PowerShell to download additional files.
Malware/backdoor that uses PowerShell commands to download additional files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.