Ares is a Windows banking trojan in the Kronos and Osiris lineage that emerged in 2021 and has been observed in financially motivated campaigns, including spam activity targeting German speakers and later operations aimed at financial institutions in Mexico. It appears to be under active development and is associated with the same criminal ecosystem that operated Osiris and used custom packers such as DarkCrypter and BMPack to hinder analysis and protect payloads.
Ares retains core banking-trojan functionality while expanding into a modular malware platform. It supports web-inject delivery and command-driven loading of additional components, including an in-memory stealer plugin and development-stage remote access functionality such as VNC support. The stealer component can collect system information and steal credentials, cookies, payment-card data, cryptocurrency-wallet data, and files from browsers, email clients, FTP clients, VPN clients, instant messengers, and other local applications. Ares also includes keylogging support and can exfiltrate collected data to command-and-control infrastructure.
The malware uses hashed API resolution derived from Kronos, scheduled-task persistence, and multiple hardcoded command-and-control endpoints. Later versions added a domain generation algorithm as a fallback mechanism when primary infrastructure is unavailable, improving resilience against disruption. Observed targeting and web-inject development indicate a focus on online banking fraud and credential theft against financial-sector victims. High-confidence reporting links Ares closely to the broader Kronos-derived malware ecosystem rather than to any legitimate remote administration tool of the same name.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The report analyzes three RATs recently used by the group in attacks, namely Geta, Ares, and Desk RAT.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The Ares malware author has altered the original Kronos source code to create new Windows API hash values for dynamically resolving NTDLL functions.
The first variant decrypts the next-stage payload using Blowfish... The second variant of the DarkCrypter packer embeds the second-stage payload in a compressed format... BMPack first decrypts embedded data using an XOR-based algorithm, followed by RC4.
The Ares malware author appears to be testing web injects to insert HTML content and JavaScript into a targeted website. While the Ares C2 server is not currently serving a dynamic web inject configuration, recent samples contain the following hardcoded configuration targeting BBVA Mexico
The Ares malware author appears to be testing web injects to insert HTML content and JavaScript into a targeted website. While the Ares C2 server is not currently serving a dynamic web inject configuration, recent samples contain the following hardcoded configuration targeting BBVA Mexico
Osiris introduced several new features including TOR for command and control (C2) communications... Most Ares samples currently do not communicate with C2 servers over TOR... Some Ares samples attempt to address this limitation by hardcoding a large number of C2 URLs in the binary.
Ares samples contain one or more hardcoded URLs that are used as the primary C2 channel.
The command 0x6 that downloads, decompresses, and maps a PE file into memory, and executes it... observed this Ares command being used to download a file from the URL http://mydynamite.dynv6[.]net/panel/upload/stealer.dll.
91 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan referenced as used in recent Transparent Tribe (APT36) activity.
Banking trojan based on the Osiris malware family and ultimately forked from Kronos. The updated variant adds a fallback DGA for command-and-control resilience, supports web injects, and is used to monetize compromised systems through activities such as wire fraud and potentially ransomware.
Actively developed Kronos-derived banking trojan with modified C2 communications, persistence via scheduled task, plugin/module loading, web inject support, keylogging/report upload behavior, and the ability to download and execute Ares Stealer and other modules such as a VNC plugin.
Named malware/tool family listed as detectable via favicon hash hunting of exposed infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.