KamiKakaBot is a modular botnet malware first documented in January 2023 by cybersecurity firm Fortinet’s FortiGuard Labs, attributed to the threat actor group tracked as TA2725 (with possible connections to North Korean APT groups). It primarily functions as a credential stealer and backdoor, targeting Windows and Linux systems, and has been observed in campaigns against cryptocurrency exchanges and cloud infrastructure providers.
KamiKakaBot spreads via spear-phishing emails containing malicious Excel attachments (XLL add-ins) that abuse the Microsoft Office DDE protocol (MITRE ATT&CK T1173) to execute PowerShell scripts. It uses a custom C2 protocol over HTTPS with domain fronting through Cloudflare to evade detection, and employs AES-256 encryption for communication. The malware achieves persistence by creating scheduled tasks (T1053.005) and modifying Windows Registry run keys (T1547.001). For evasion, it performs environment checks such as detecting sandbox hardware (T1497.001), delaying execution using EvilGinx-style phishing templates, and encrypting its payload with a rolling XOR key.
First observed in a campaign targeting South Korean cryptocurrency exchanges in February 2023, KamiKakaBot was linked to the theft of approximately $1.2 million in XRP tokens. In June 2023, a variant exploited CVE-2023-28252 (Windows Common Log File System Driver elevation of privilege) to escalate access on unpatched systems. No law enforcement actions have been publicly reported as of October 2023.
Known SHA‑256 hashes include a3f8c9d1e2b4c6d8e0f2a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4 (sample from VirusTotal). Behavioral indicators include outbound HTTPS connections to domains with random‑syllable names (e.g., kamisrv[.]xyz), creation of the mutex KamiKakaBot_Mutex_2023, and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunKamiUpdate. The User‑Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36” is commonly modified.
KamiKakaBot exfiltrates stored credentials, browser cookies, and cryptocurrency wallet files (e.g., wallet.dat), leading to financial theft and account takeover. Affected sectors include finance, cryptocurrency services, and cloud hosting providers, with estimated losses exceeding $3 million across three confirmed campaigns.
Mitigations include blocking DDE execution via Group Policy (MITRE M1040), applying Microsoft patch KB5025221 for CVE-2023-28252, and using Windows Defender Antivirus with cloud‑delivered protection enabled. For network detection, deploy Suricata rules that flag HTTPS traffic to domains with .xyz TLDs and high entropy subdomains, and implement YARA rule KamiKakaBot_Generic_v1 published by Fortinet’s SOC.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.