KasperAgent is a Microsoft Windows malware family used in targeted espionage operations in the Middle East and associated in public reporting with the Arid Viper ecosystem. Activity involving KasperAgent has targeted users primarily in the United States, Israel, the Palestinian Territories, and Egypt, with some operations also affecting media organizations. The malware has been distributed through spearphishing emails containing shortened malicious links and through fake news or lure sites that entice victims to download malicious files. Some delivery chains also used a .NET loader to deploy the malware while displaying decoy documents to the victim.
KasperAgent primarily functions as a downloader and reconnaissance implant. Core variants collect environment information from infected systems and communicate with remote command-and-control infrastructure over HTTP to receive further instructions or retrieve additional payloads. The malware establishes persistence on compromised hosts and has been observed masquerading as legitimate software to reduce suspicion.
More capable KasperAgent variants extend beyond reconnaissance and downloading. Reported functionality includes theft of stored browser passwords from Firefox and Chrome, screenshot capture, keylogging, arbitrary command execution, enumeration of removable drives, collection and copying of files for theft, self-update capability, and exfiltration of stolen data in encrypted compressed archives. These behaviors make KasperAgent a flexible espionage platform suitable for initial foothold establishment, victim profiling, and follow-on collection.
Public reporting has linked KasperAgent with the related Windows malware family Micropsia and with Android malware families used in the same broader campaign. Researchers identified shared infrastructure and overlapping operational patterns across these toolsets. While some reporting associates the broader activity cluster with Arid Viper, also known as APT-C-23 or Desert Falcon, attribution of specific KasperAgent operations has not always been stated with full confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2017, Palo Alto Networks Unit 42 reported on two malware families: KasperAgent and Micropsia, and today we still see variants of Micropsia in use.
"...to creating custom developed ones such as KASPERAGENT and MICROPSIA."
16 distinct techniques documented for this family, organized by ATT&CK tactic.
https[:]//tinyurl[.]com/7412593655 --> https[:]//uc4688d6b7cd62aec5fe2018c3d1[.]dl[.]dropboxusercontent[.]com/.../file?dl=1
171 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
KasperAgent is a named malware family/tool used in targeted attacks in the Middle East and associated in the content with Arid Viper activity.
Custom-developed backdoor/tool referenced as part of Molerats' historical toolset.
Mentioned only in a next-article link, not part of the Amnesia report.
A Windows malware family used in targeted attacks. It primarily acts as a basic reconnaissance tool and downloader for further payloads, establishes persistence via a Run key, communicates over HTTP with C2 infrastructure, and in some variants adds password theft, screenshots, keylogging, arbitrary command execution, removable-drive file collection, malware updating, and encrypted file exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.