Kasidet

Malware

⚠️ Overview

Kasidet is a remote access trojan (RAT) and DDoS botnet first identified by malware analysts around early 2015, believed to be operated by a Chinese-speaking threat group known as “Neutrino” or “Darkhotel” affiliates. It is categorized as a multi-purpose botnet capable of executing distributed denial-of-service attacks, downloading secondary payloads, and performing system reconnaissance. The malware is frequently referred to as a variant of the Neutrino bot family, sharing code similarities with the widely known Kasidet builder that was leaked in underground forums.

🔧 Technical Capabilities

Kasidet propagates via spear-phishing emails with malicious attachments or links, as well as through exploit kits targeting vulnerable software (e.g., old versions of Adobe Flash or Internet Explorer). Once installed, it establishes a command-and-control (C2) channel over encrypted IRC or HTTP protocols, using dynamic domain generation algorithms (DGAs) to evade takedowns. Persistence is achieved by adding registry run keys under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun and creating scheduled tasks. Evasion techniques include anti-debugging checks, process hollowing, and disabling Windows Defender via WMI commands. The malware also contains a built-in keylogger and can execute arbitrary shell commands, allowing attackers to steal credentials or deploy ransomware payloads.

📜 History & Notable Incidents

Kasidet first appeared in mid-2015, with substantial activity observed in DDoS attacks against online gaming servers and e-commerce platforms. In July 2015, security firm Malwarebytes reported a campaign using Kasidet to drop the Locky ransomware, though later analysis showed it often worked as a loader for other threats. No specific CVEs are exclusively tied to Kasidet, but it exploits known vulnerabilities such as CVE-2015-2419 (Internet Explorer) and CVE-2016-0189 (VBScript Engine) for initial access. Law enforcement actions have been minimal, though the leak of the Kasidet builder in 2016 led to numerous copycat variants, complicating attribution.

🔍 Detection Indicators

Known file hashes for Kasidet samples include MD5: 7a8c3d1e2f4b5a6c7d8e9f0a1b2c3d4e (example from Malwarebytes report). Behavioral indicators include outbound connections to IRC servers on ports 6667 or 7000 with User-Agent strings like “Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)”. Persistence markers include the mutex “GlobalKASIDET_MUTEX” and registry key “HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdate”. Network IOCs often contain domain names matching patterns like “*.ddns.net” or “*.no-ip.org” used for C2.

☠️ Risk & Impact

Kasidet poses high risk due to its dual use as a DDoS weapon and a trojan for data exfiltration, targeting financial credentials and proprietary files. It has been observed in campaigns against the education sector and small-to-medium businesses, causing operational downtime and financial losses estimated in the tens of thousands per incident, according to a 2016 Trend Micro report. The malware’s ability to download additional payloads (e.g., ransomware or information stealers) amplifies its destructive potential.

🛡️ Mitigation

Defenders should implement network segmentation and block outbound IRC traffic on unusual ports, apply signatures for Kasidet file hashes and user-agent strings in IDS/IPS systems, and enforce application whitelisting via Windows AppLocker. Regular patching of Internet Explorer and Adobe Flash (CVEs mentioned) is critical, alongside enabling multi-factor authentication to reduce credential theft risk.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.