KARAE is malware that has been observed using public cloud-based storage providers for command-and-control communications. It was distributed to South Korean victims through torrent file-sharing websites, where it was disguised as or bundled with a YouTube video downloader application as a lure. The available content directly associates KARAE with abuse of legitimate cloud services for C2 and with torrent-based delivery targeting South Korean users. No additional high-confidence details on payload capabilities, specific operators, or indicators of compromise are provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that can use public cloud storage providers for command-and-control.
Malware that uses public cloud-based storage providers for command and control.
Malware distributed via torrent sites using a trojanized YouTube downloader lure, targeting South Korean victims.
Malware distributed via torrent sites using a trojanized YouTube video downloader lure, targeting South Korean victims.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.