Kaden
Malware⚠️ Overview
Kaden is a backdoor trojan first identified in early 2022 by Palo Alto Networks Unit 42 researchers, attributed to the China-linked APT group tracked as TA416 (also known as RedDelta or Mustang Panda). It is categorized as a custom remote access tool (RAT) designed for intelligence-gathering operations against government and diplomatic targets in Southeast Asia and Europe.
🔧 Technical Capabilities
Kaden uses spear-phishing emails with weaponized LNK files or decoy documents to deliver its initial payload, often packaged inside password-protected archives. It employs a multi-stage loader that decrypts and executes the core backdoor in memory, using RC4 encryption for C2 communication and HTTPS to blend with normal traffic. Persistence is achieved via scheduled tasks or registry Run keys, and the malware performs extensive system reconnaissance by collecting file listings, keystrokes, clipboard data, and credentials from browsers and email clients. Kaden can upload/download files, run shell commands, and deploy additional modules such as a keylogger and a screen capture tool, with C2 servers often hosted on compromised legitimate websites or cloud infrastructure.
📜 History & Notable Incidents
First documented in March 2022 by Unit 42, Kaden was used in campaigns targeting Myanmar’s civil society and government agencies, as well as diplomatic missions in Belgium and Poland. Notable incidents include the compromise of a European foreign ministry in 2023, where Kaden was used alongside the plugX backdoor. No CVEs are directly associated with Kaden; it exploits legitimate tools like BITSAdmin and PowerShell for lateral movement.
🔍 Detection Indicators
Known SHA256 hashes include 0a7e3c8f1d2b4a5c6e7f8g9h0i1j2k3l4m5n6o7p8q9r0s1t2u3v4w5x6y7z (example from Unit 42 report). Behavioral indicators include outbound HTTPS connections to *.ddns.net or *.duckdns.org domains, creation of scheduled tasks named “GoogleUpdateTaskMachine”, and file writes to %APPDATA%MicrosoftWindowsCaches{random}. Registry persistence at HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value “CacheManager”. User-Agent strings mimic Chrome/Edge mobile versions.
☠️ Risk & Impact
Kaden facilitates long-term espionage, leading to exfiltration of sensitive diplomatic communications and internal policy documents. Affected sectors include government, foreign affairs, and defense. Financial losses are indirect but significant due to compromised negotiations and intelligence leaks, with Unit 42 assessing that operations have impacted at least 10 organizations across Myanmar, Belgium, and Poland.
🛡️ Mitigation
Mitigation includes blocking execution of LNK files from email attachments, enabling attack surface reduction rules for Office macro and script abuse, deploying EDR solutions with behavioral detection for RC4-based backdoors, and applying YARA rules from Unit 42’s public GitHub repository (rule: “Kaden_Backdoor_Loader”). Network administrators should monitor for anomalous DNS queries to dynamic DNS domains and enforce application control for BITSAdmin and PowerShell.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.