KAK, also referred to as Kagou Anti Kro$oft, is a 1999 JavaScript worm targeting Microsoft Windows systems. It propagates through Outlook Express by exploiting CVE-1999-0668, an Internet Explorer/Outlook Express HTML email rendering vulnerability involving the ActiveX control Scriptlet.Typelib, which was marked safe for scripting and could be abused to create arbitrary files. The worm embeds exploit code in an email signature so that infection can occur when a message is viewed or previewed in Outlook Express. KAK drops a malicious HTA file, typically "kak.hta," into the Windows Startup folder, where it is later executed by Windows Scripting Host. For persistence, it adds a Run key at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cAg0u and also edits AUTOEXEC.BAT to launch the worm on startup and delete artifacts, including references to C:\Windows\Start Menu\Programs\StartUp\kak.hta, in an apparent attempt to hinder tracking. When kak.hta runs, it sets the user’s email signature to include code that infects other systems. Reported behaviors also include displaying a minimized window titled "Driver Memory Error" and a message stating "S3 Driver Memory Alloc Failed!" On the first day of every month at 6:00 pm, KAK triggers a payload using SHUTDOWN.EXE to initiate a shutdown and displays the message "Kagou-anti-Kro$oft says not today!" The provided content does not identify any associated threat actor or specific industry targeting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content includes a 'Malware' list under 'Hacking in the 1990s' that names: 'CIH, Happy99, Hare, KAK, Melissa, Michelangelo, Staog'.
Timeline ... Malware ... CIH ... Happy99 ... Hare ... KAK ... Melissa ... Michelangelo ... Staog
The content includes a 1990s timeline section listing malware, including: "Malware CIH Happy99 Hare KAK Melissa Michelangelo Staog".
A Windows-targeting JavaScript email worm that propagates via Outlook Express/Internet Explorer HTML rendering by abusing the Scriptlet.Typelib ActiveX control to drop and execute an HTA (kak.hta) from the StartUp folder, persists via Run key and AUTOEXEC.BAT modifications, and performs a scheduled shutdown/popup payload on the first day of each month.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.