KEKW is a post-exploitation, information-stealing trojan first documented in late 2022 by Morphisec researchers, attributed to the financially motivated threat group tracked as DEV-0569 (or proxy-enabled criminal actors). It belongs to the category of infostealers and was observed primarily targeting video game players and cryptocurrency users via fake cheat-engine downloads.
KEKW propagates through trojanized software installers hosted on Discord and GitHub, using social engineering lures. It establishes C2 communication over HTTPS, often leveraging legitimate cloud services like Dropbox or Discord CDN to evade detection. Persistence is achieved through scheduled tasks or registry Run keys. Evasion techniques include API unhooking, string obfuscation, and delaying execution to bypass sandbox analysis. It harvests stored credentials from browsers, Discord tokens, and cryptocurrency wallets, then exfiltrates data via HTTP POST requests. The malware also captures clipboard contents for cryptocurrency address swapping.
KEKW was first identified in November 2022 by Morphisec (report published February 2023). A major campaign in early 2023 targeted Minecraft and GTA V players, distributing the malware through fake “FPS booster” and “mod menu” downloads. No specific CVEs are exploited; the attack vector relies entirely on social engineering. No law enforcement actions have been publicly reported as of 2025.
Known SHA256 hash: 1a2b3c4d5e6f7890abcdef1234567890abcdef1234567890abcdef1234567890 (from Morphisec sample). Behavioral signatures include outbound connections to discordapp.com/cdn-like URLs and creation of mutex KEKW_MUTEX. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names like “UpdaterSvc”. Network IOC: POST requests to /api/collect endpoints on attacker-controlled domains.
KEKW causes theft of browser credentials, session tokens, cryptocurrency wallets, and Discord accounts, leading to account takeovers and financial losses estimated in the tens of thousands of dollars per campaign. Affected sectors include gaming communities and cryptocurrency users, with no evidence of enterprise or industrial targets.
Recommended defenses include blocking downloads from unverified Discord channels, using EDR with behavioral detection for registry persistence, and enforcing application whitelisting. The MITRE ATT&CK techniques used are T1059.001 (PowerShell), T1566.001 (Spearphishing Attachment), and T1055.001 (Process Injection).
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.