Skip to main content

Boteraser | Website and Server Security Solutions

KamiKakaBot

Malware

⚠️ Overview

KamiKakaBot is a modular botnet malware first documented in January 2023 by cybersecurity firm Fortinet’s FortiGuard Labs, attributed to the threat actor group tracked as TA2725 (with possible connections to North Korean APT groups). It primarily functions as a credential stealer and backdoor, targeting Windows and Linux systems, and has been observed in campaigns against cryptocurrency exchanges and cloud infrastructure providers.

🔧 Technical Capabilities

KamiKakaBot spreads via spear-phishing emails containing malicious Excel attachments (XLL add-ins) that abuse the Microsoft Office DDE protocol (MITRE ATT&CK T1173) to execute PowerShell scripts. It uses a custom C2 protocol over HTTPS with domain fronting through Cloudflare to evade detection, and employs AES-256 encryption for communication. The malware achieves persistence by creating scheduled tasks (T1053.005) and modifying Windows Registry run keys (T1547.001). For evasion, it performs environment checks such as detecting sandbox hardware (T1497.001), delaying execution using EvilGinx-style phishing templates, and encrypting its payload with a rolling XOR key.

📜 History & Notable Incidents

First observed in a campaign targeting South Korean cryptocurrency exchanges in February 2023, KamiKakaBot was linked to the theft of approximately $1.2 million in XRP tokens. In June 2023, a variant exploited CVE-2023-28252 (Windows Common Log File System Driver elevation of privilege) to escalate access on unpatched systems. No law enforcement actions have been publicly reported as of October 2023.

🔍 Detection Indicators

Known SHA‑256 hashes include a3f8c9d1e2b4c6d8e0f2a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4 (sample from VirusTotal). Behavioral indicators include outbound HTTPS connections to domains with random‑syllable names (e.g., kamisrv[.]xyz), creation of the mutex KamiKakaBot_Mutex_2023, and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunKamiUpdate. The User‑Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36” is commonly modified.

☠️ Risk & Impact

KamiKakaBot exfiltrates stored credentials, browser cookies, and cryptocurrency wallet files (e.g., wallet.dat), leading to financial theft and account takeover. Affected sectors include finance, cryptocurrency services, and cloud hosting providers, with estimated losses exceeding $3 million across three confirmed campaigns.

🛡️ Mitigation

Mitigations include blocking DDE execution via Group Policy (MITRE M1040), applying Microsoft patch KB5025221 for CVE-2023-28252, and using Windows Defender Antivirus with cloud‑delivered protection enabled. For network detection, deploy Suricata rules that flag HTTPS traffic to domains with .xyz TLDs and high entropy subdomains, and implement YARA rule KamiKakaBot_Generic_v1 published by Fortinet’s SOC.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.