Kenzero is a trojan first reported by Symantec on 2009-11-27 that spread via peer-to-peer file-sharing networks, including infected hentai anime video files. After a victim downloaded and ran an infected file, the malware displayed a fake installation screen to solicit personal information, logged the victim’s browsing history, and published that information in a public online database. It was designed for blackmail: victims were shown a dialog box or sent an email demanding approximately $16 USD to remove their browsing history from the database. The content states that Kenzero was believed to have originated in Japan and was said by cited experts to be linked to the same cybercriminal group associated with Zeus and Koobface. High-confidence behaviors directly mentioned include P2P propagation, use of fake installer prompts for personal data collection, browsing-history theft, public exposure of victim data, and extortion demands.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A P2P-distributed trojan/infostealer that tricks victims with a fake installation screen, collects personal information, logs browsing history, publishes that history online, and extorts victims for a fee to remove the exposed data.
2009 Jabber Zeus Kenzero Koobface MegaPanzer MiniPanzer SpyEye Waledac
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.