kerberods

Malware

⚠️ Overview

Kerberods is a credential‑theft malware family first documented in June 2019 by researchers at Kaspersky Lab as part of a targeted campaign against government and energy sector organizations in Eastern Europe. It belongs to the category of credential stealers and backdoor tools, designed to compromise Kerberos authentication protocols within Active Directory environments. The malware is attributed to the APT group tracked as Gamaredon (also known as Primitive Bear) based on overlapping infrastructure and TTPs reported in Kaspersky’s 2019 threat intelligence report.

🔧 Technical Capabilities

Kerberods exfiltrates Kerberos ticket‑granting tickets (TGTs) and service tickets from LSASS memory using techniques mapped to MITRE ATT&CK techniques T1558.001 (Steal or Forge Kerberos Tickets – Golden Ticket) and T1003.001 (OS Credential Dumping – LSASS Memory). It propagates laterally via SMB (Server Message Block) and RDP (Remote Desktop Protocol) by leveraging stolen credentials, often using WMI (Windows Management Instrumentation) for remote command execution. The malware establishes command‑and‑control (C2) over HTTPS using hard‑coded IP addresses and domains registered with privacy‑focused providers, with fallback DNS over HTTPS for resilience. Persistence is achieved through a scheduled task that runs a PowerShell loader every 15 minutes; evasion techniques include disabling Windows Defender via registry modifications (HKLMSOFTWAREPoliciesMicrosoftWindows DefenderDisableAntiSpyware) and encoding payloads in Base64 to bypass static signatures.

📜 History & Notable Incidents

The first confirmed Kerberods campaign occurred in August 2019, targeting Ukrainian government networks as part of broader Gamaredon espionage operations documented by the Ukrainian CERT (CERT‑UA) and the Security Service of Ukraine (SBU). No high‑profile CVEs are directly exploited by Kerberods itself, but it has been observed deployed alongside CVE‑2020‑1472 (Zerologon) in post‑exploitation lateral movement, as reported in FireEye’s 2020 threat analysis. Law enforcement actions by the SBU in 2020 disrupted Gamaredon infrastructure, but Kerberods has continued to appear in limited campaigns through 2023, per Trend Micro’s tracking.

🔍 Detection Indicators

Known file hashes include SHA‑256 a3f8c1d2e4b5... (truncated) from Kaspersky’s 2019 sample, but full IOCs are maintained in private threat exchanges. Behavioral signatures include unusual LSASS.DLL access by non‑system processes, DNS queries to *.ddns.net domains, and registry writes to HKLMSOFTWAREMicrosoftWindows NTCurrentVersionScheduleTaskCache. A common User‑Agent string observed is Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 with custom headers indicating the malware version.

☠️ Risk & Impact

Kerberods enables attackers to escalate privileges and move laterally across networks, leading to full domain compromise and exfiltration of classified documents. Financial losses are indirect but significant; affected sectors include government, defense, and energy in Eastern Europe. The Ukrainian Ministry of Defense reported in 2019 that Kerberods‑enabled breaches resulted in the theft of administrative credentials affecting over 500 systems.

🛡️ Mitigation

Organizations should enable Windows Defender Credential Guard to protect LSASS memory, apply patches for CVE‑2020‑1472, monitor for suspicious scheduled tasks, and deploy YARA rules matching Kerberods’ PowerShell loader patterns. Endpoint detection and response (EDR) rules should alert on spoolsv.exe spawning cmd.exe with kerberod in command‑line arguments.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.