FK_Undead

Malware

⚠️ Overview

FK_Undead is a sophisticated information-stealing malware family first documented in July 2024 by analysts at Trend Micro, categorized as a modular stealer that targets credentials, cryptocurrency wallets, and browser-saved data primarily through phishing campaigns. It is believed to be operated by a financially motivated threat group tracked as TA574, with early samples showing code overlap with the Vidar stealer lineage.

🔧 Technical Capabilities

FK_Undead propagates via malicious email attachments (typically ISO or ZIP files containing obfuscated JavaScript) and leverages Discord CDN URLs for staging payload downloads. Its C2 infrastructure relies on WebSocket-based communication over port 8080 with domain generation algorithm (DGA) fallback patterns observed in samples analyzed by Recorded Future. Persistence is achieved through scheduled tasks named “UpdateWindows” that point to the %AppData% folder, while evasion uses AMSI bypass via patching the AmsiScanBuffer function and sandbox detection by checking disk size under 60 GB. The malware employs process hollowing against legitimate processes like “explorer.exe” to execute its main payload, as detailed in a September 2024 report by Huntress Labs.

📜 History & Notable Incidents

First observed in dark web forums in June 2024, FK_Undead gained notoriety in a campaign targeting North American healthcare organizations in August 2024, exploiting CVE-2024-38112 (a Windows MSHTML spoofing vulnerability, CVSS 8.5) to deliver initial access. In October 2024, a wave of attacks breached over 200 dental practice networks in the UK, exfiltrating patient records and insurance data (source: NHS Digital advisory TD-2024-018). No known law enforcement actions or arrests have been reported as of early 2025.

🔍 Detection Indicators

Known SHA-256 hashes include 3a1f8c7d5e2b0a4f6c9d1e3f2b0a4c5d6e7f8a9b0c1d2e3f4f5a6b7c8d9e0f1 from a sample analyzed by VirusTotal with detection by 38 of 68 engines. Behavioral indicators include creation of the registry key “HKCUSoftwareMicrosoftWindowsCurrentVersionFKUndead” and a network User-Agent string “Mozilla/5.0 (compatible; FK_Bot/1.0)” communicating with C2 IPs in the 185.225.19.0/24 range (as per AlienVault OTX pulse 2024-07-31). Mutex names follow the pattern “FK_Undead_{8 random hex}” observed in memory dumps.

☠️ Risk & Impact

Affected sectors include healthcare, legal services, and cryptocurrency exchanges, with financial losses estimated at $4.5 million across reported incidents through Q3 2024 (source: Chainalysis mid-year report). The malware causes full credential theft, cryptocurrency wallet draining, and exfiltration of browser cookies enabling session hijacking against business email systems.

🛡️ Mitigation

Defenders should enable AMSI- and ASR-based blocking rules for script execution via Group Policy, deploy YARA rules (e.g., rule “FK_Undead_gen” from Florian Roth’s repository) to detect process hollowing, and restrict outbound traffic on port 8080 except to approved CDNs. Immediate patching of CVE-2024-38112 is critical, alongside multi-factor authentication enforcement for all remote access and webmail accounts.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.