Kidkadi is a second-stage loader associated with the GachiLoader malware campaign analyzed by Check Point Research. It is delivered in a malware distribution operation dubbed the “YouTube Ghost Network,” in which compromised YouTube accounts post lure videos themed around game cheats and cracked software that direct victims to password-protected archives hosted externally. In observed cases, the overall infection chain ultimately delivered the Rhadamanthys infostealer.
Kidkadi is a Node.js native addon stored as a .node file and loaded as a DLL via Node.js dlopen from GachiLoader. One GachiLoader variant drops Kidkadi as kidkadi.node together with an embedded payload. Kidkadi implements a previously undocumented PE injection method that Check Point named “Vectored Overloading.” According to the reporting, this technique loads a legitimate DLL such as wmp.dll, creates an SEC_IMAGE section from it, overwrites that section with a malicious payload, maps it with NtMapViewOfSection, and abuses Vectored Exception Handling and hardware breakpoints to emulate syscalls including NtOpenSection and NtMapViewOfSection during LoadLibrary so that Windows maps the malicious PE from memory while it appears backed by the legitimate DLL.
High-confidence behavioral details directly described in the content are that Kidkadi abuses VEH, uses hardware breakpoints, and performs PE injection by replacing a legitimate DLL mapping on the fly with malicious code. It is specifically described as a second-stage loader deployed by GachiLoader. The surrounding campaign targeted Windows users seeking cheats or cracked software via malicious YouTube links. A directly mentioned artifact is the dropped filename kidkadi.node; a directly mentioned DLL used in the technique is wmp.dll. The malware and technique were publicly analyzed by Check Point Research.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Second-stage loader that abuses Windows Vectored Exception Handling (VEH) using a technique described as 'Vectored Overloading' to load a malicious payload.
Second-stage loader delivered by GachiLoader as a Node.js native addon (.node/DLL). It executes an embedded PE payload using reflective loading and a novel PE injection approach (“Vectored Overloading”) that abuses Vectored Exception Handling (VEH) plus hardware breakpoints to emulate NtOpenSection/NtMapViewOfSection and swap a legitimate DLL-backed section (e.g., wmp.dll) with a malicious in-memory PE during LoadLibrary (e.g., amsi.dll).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.