Symantec documented Infostealer.Kenzero, a credential- and privacy-stealing trojan distributed through malicious files posing as adult game content. Once executed, the malware harvested sensitive information from infected systems, including user activity and locally stored data, and was associated with attempts to expose victims by leveraging the stolen information.
The threat stood out for combining conventional information theft with coercive tactics aimed at embarrassing users into paying money. The case highlighted how socially engineered malware campaigns can use lure content to drive infections, then monetize access through both data theft and extortion, creating legal, financial, and reputational risk for affected individuals.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Symantec released a security response write-up documenting Infostealer.Kenzero, establishing public vendor reporting on the malware and its behavior.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.