Kronos is a Windows banking trojan first identified in 2014 and marketed in underground crimeware forums as a kit for financial fraud, credential theft, and account takeover. It is part of the post-Zeus generation of banking malware and has been associated with theft of online banking credentials through keylogging, form grabbing, web injection, and man-in-the-browser techniques. Reported functionality also includes hidden VNC-style remote interaction used to facilitate fraudulent transactions and browser-session abuse against financial services.
Kronos has been delivered through multiple intrusion chains, including phishing emails with malicious macro-enabled documents, exploit-kit-driven drive-by compromise, and downstream delivery by malware distribution services such as GootLoader and PrivateLoader. Campaigns have used lures themed around invoices, banking notices, and other business documents, and some infections have involved intermediate loaders before the final Kronos payload was executed.
Later variants observed from 2018 onward retained substantial code overlap with earlier Kronos builds while shifting command-and-control communications to Tor hidden services. Those variants were used in campaigns targeting financial institutions and users in countries including Germany, Japan, and Poland, with web inject configurations tailored to regional banks. Kronos has also appeared as part of broader criminal ecosystems in which it served as an intermediate or final payload and, in at least one documented case, downloaded additional malware targeting point-of-sale environments.
Kronos is widely regarded as the predecessor of the Osiris and Ares banking trojan lineage. Osiris was presented as an updated Kronos-derived banking trojan with Tor-based communications and continued credential theft and web-inject functionality. Ares, another descendant, expanded the lineage with modular stealer capabilities, persistence components, and broader theft from browsers, VPN clients, email clients, and cryptocurrency wallets. Kronos has also been discussed in connection with UPAS Kit due to technical similarities and shared implementation patterns.
The malware has been linked in public legal proceedings to Marcus Hutchins and an associate involved in developing and selling Kronos and UPAS Kit during the mid-2010s. Kronos remained a notable banking-malware family because of its role in credential theft, browser manipulation, and its influence on later banking trojan development.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Spelevo Exploit Kitは2つの脆弱性(CVE-2018-8174とCVE-2018-15982)を悪用することが報告されていますが、PseudoGateによる攻撃ではCVE-2018-15982のみが観測されています。CVE-2018-15982はAdobe Flash PlayerのRCEの脆弱性です。
The document used CVE-2017-11882 (the “Equation Editor” exploit) to download and execute the new version of Kronos from http://mysit[.]space/123//v/0jLHzUW. | The Kronos banking Trojan was first discovered in 2014 and was a steady fixture in the threat landscape for a few years before largely disappearing. Now a new variant has appeared... There is some speculation and circumstantial evidence suggesting that this new version of Kronos has been rebranded “Osiris” and is being sold on underground markets.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
He pleaded guilty to entering a conspiracy to create and distribute malware, and in aiding and abetting its distribution.
When enabling the macro on EmployeID-6283.doc, the macro will download profile.excel-sharepoint[.]com/doc/office.exe (Kronos Payload) and execute it.
UPAS Kit makes usage of multiple low-level ntdll functions and resolves their addresses during run-time... some of the resolved functions serve the purpose of being utilized as syscalls...
The document used CVE-2017-11882 (the “Equation Editor” exploit) to download and execute the new version of Kronos
A trojan is any type of malicious program disguised as a legitimate one.
Process Injection The injection conducted by the malware depends on the system architecture... it would create the ‘explorer.exe’ process and inject its own image into it... Finally... adjust the value of EAX in the Context struct... and then resume execution by calling the NtSetContextThread function. If this fails, it will attempt to spawn the target function directly with the CreateRemoteThread function.
User Land Rootkit Functionality UPAS Kit uses a pretty straight forward inline hooking mechanism... The following ntdll.dll functions are hooked and are intended to hide the malware’s artifacts, thus making it covert.
Trojans evade detection by having dormant capabilities, hiding components in other files, forming part of a rootkit, or using heavy obfuscation.
UPAS Kit makes usage of multiple low-level ntdll functions and resolves their addresses during run-time... It simply takes the string field of each entry and resolves the corresponding address using the Win32 API function GetProcAddress.
First it copies itself into a new directory under %APPDATA%, named ‘Microsoft’ as well as to the %TEMP% directory.
Process Injection The injection conducted by the malware depends on the system architecture... it would create the ‘explorer.exe’ process and inject its own image into it... Finally... adjust the value of EAX in the Context struct... and then resume execution by calling the NtSetContextThread function. If this fails, it will attempt to spawn the target function directly with the CreateRemoteThread function.
At this point, the code spawns the ImagingDevices.exe process and injects itself into it via process hollowing.
The following ntdll.dll functions are hooked and are intended to hide the malware’s artifacts... NtQueryDirectoryFile: Hides the directory in which the malware copy resides... NtEnumerateValueKey: Hides the registry run key corresponding to the malware... NtWriteFile: Avoids the action if the target file is the malware’s binary.
both present an attempt to elevate the malware’s process token to SeDebugPrivilege, which is not mandatory for the injection to succeed.
When the string table is decrypted, the first 41 entries are identical to older Kronos variants with eight new string additions... to detect sandbox environments... If the anti-analysis checks pass, the packer proceeds to the next step.
It also has keylogging and hidden VNC functionality to help with its “banker” activities.
Osiris introduced several new features including TOR for command and control (C2) communications... Most Ares samples currently do not communicate with C2 servers over TOR... Some Ares samples attempt to address this limitation by hardcoding a large number of C2 URLs in the binary.
69 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A trojan delivered as a final payload by Gootloader in the campaigns described.
A banking trojan briefly distributed to European PrivateLoader bots and executed together with Vidar.
A trojan, likely banking-focused from the article’s wording, identified as one of the payloads delivered by Gootloader.
Banking trojan that is the original ancestor of Ares via Osiris; Ares also retains and modifies Kronos source code elements such as API hashing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.