Kaden is a backdoor trojan first identified in early 2022 by Palo Alto Networks Unit 42 researchers, attributed to the China-linked APT group tracked as TA416 (also known as RedDelta or Mustang Panda). It is categorized as a custom remote access tool (RAT) designed for intelligence-gathering operations against government and diplomatic targets in Southeast Asia and Europe.
Kaden uses spear-phishing emails with weaponized LNK files or decoy documents to deliver its initial payload, often packaged inside password-protected archives. It employs a multi-stage loader that decrypts and executes the core backdoor in memory, using RC4 encryption for C2 communication and HTTPS to blend with normal traffic. Persistence is achieved via scheduled tasks or registry Run keys, and the malware performs extensive system reconnaissance by collecting file listings, keystrokes, clipboard data, and credentials from browsers and email clients. Kaden can upload/download files, run shell commands, and deploy additional modules such as a keylogger and a screen capture tool, with C2 servers often hosted on compromised legitimate websites or cloud infrastructure.
First documented in March 2022 by Unit 42, Kaden was used in campaigns targeting Myanmar’s civil society and government agencies, as well as diplomatic missions in Belgium and Poland. Notable incidents include the compromise of a European foreign ministry in 2023, where Kaden was used alongside the plugX backdoor. No CVEs are directly associated with Kaden; it exploits legitimate tools like BITSAdmin and PowerShell for lateral movement.
Known SHA256 hashes include 0a7e3c8f1d2b4a5c6e7f8g9h0i1j2k3l4m5n6o7p8q9r0s1t2u3v4w5x6y7z (example from Unit 42 report). Behavioral indicators include outbound HTTPS connections to *.ddns.net or *.duckdns.org domains, creation of scheduled tasks named “GoogleUpdateTaskMachine”, and file writes to %APPDATA%MicrosoftWindowsCaches{random}. Registry persistence at HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value “CacheManager”. User-Agent strings mimic Chrome/Edge mobile versions.
Kaden facilitates long-term espionage, leading to exfiltration of sensitive diplomatic communications and internal policy documents. Affected sectors include government, foreign affairs, and defense. Financial losses are indirect but significant due to compromised negotiations and intelligence leaks, with Unit 42 assessing that operations have impacted at least 10 organizations across Myanmar, Belgium, and Poland.
Mitigation includes blocking execution of LNK files from email attachments, enabling attack surface reduction rules for Office macro and script abuse, deploying EDR solutions with behavioral detection for RC4-based backdoors, and applying YARA rules from Unit 42’s public GitHub repository (rule: “Kaden_Backdoor_Loader”). Network administrators should monitor for anomalous DNS queries to dynamic DNS domains and enforce application control for BITSAdmin and PowerShell.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.