Researchers detailed KPOT v2.0, a commercially sold information-stealing malware strain designed to harvest credentials and sensitive data from browsers, messaging applications, email clients, VPN and RDP software, FTP clients, gaming platforms, and cryptocurrency wallets including Jaxx. The malware was marketed on underground forums at a low price point, making it accessible to a broad range of threat actors, and its targeting of wallet users highlighted the growing overlap between credential theft and cryptocurrency-focused crime.
Observed delivery methods included email campaigns and exploit kits, including an RTF lure exploiting CVE-2017-11882 to launch a PowerShell-based loader that retrieved the final payload. Once executed, KPOT used encrypted strings, runtime API resolution, and an encrypted HTTP command-and-control configuration to receive tasks, exfiltrate system and credential data, and steal files matching attacker-defined rules. The analyzed variant notably used in-memory execution and no persistence, terminating after completing assigned tasks, and also checked for victims in CIS countries before exiting without infecting them.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
A reverse-engineering analysis of KPOT v2.0 documented its XOR-based string decryption, Murmur3-based API hashing, dynamic API resolution via PEB parsing, and memory-dumped API reconstruction. The analysis also detailed theft capabilities spanning browsers, messengers, email clients, VPNs, RDP, FTP clients, cryptocurrency wallets, and gaming platforms.
A SANS ISC diary analyzed a KPOT infection chain in which a PowerShell downloader fetched an obfuscated AutoIt script, a legitimate AutoIt interpreter, and an encrypted payload from show1[.]website. The analysis showed KPOT using process hollowing into dllhost.exe and extracted a decrypted sample with SHA-256 3fd4aa339bdfee23684ff495d884aa842165e61af85fd09411abfd64b9780146.
Flashpoint Intel observed KPOT Stealer targeting users of the Jaxx cryptocurrency wallet in September 2018. This showed the malware being used against cryptocurrency-related targets.
Proofpoint researchers observed KPOT Stealer being distributed through email campaigns and exploit kits beginning in August 2018. The malware was used to steal credentials and other data from infected systems.
A newer version of the malware, KPOT v2.0, was marketed on Russian-language underground hacking forums for about $100. The version analyzed by Proofpoint included in-memory execution and no persistence mechanism.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 17 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceisc.sans.edu
Open sourceproofpoint.com
Open sourceflashpoint-intel.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.