Kikothac
Malware⚠️ Overview
Kikothac is a trojan first documented by the cybersecurity firm ESET in late 2023, primarily targeting Microsoft Windows systems. It is classified as a backdoor trojan, designed to establish persistent remote access on infected machines. The malware is attributed to an unattributed cybercrime group likely operating out of Eastern Europe based on code similarities to earlier trojans like AgentTesla. No official MITRE ATT&CK ID has been assigned yet, but its behavior maps to techniques in the Execution and Persistence tactics.
🔧 Technical Capabilities
Kikothac uses spear-phishing emails with malicious Microsoft Office attachments as its primary initial access vector, leveraging social engineering to trick users into enabling macros. Once executed, the trojan drops a DLL payload that installs itself as a Windows service for persistence, using the service name “KikoService” to blend in. It establishes communication with a hard-coded command-and-control (C2) server over HTTPS, exfiltrating system information and receiving commands to download additional payloads. Evasion techniques include obfuscated string decryption using XOR keys and API hashing to avoid static detection. The trojan also disables Windows Defender via registry modifications under HKLMSOFTWAREPoliciesMicrosoftWindows Defender.
📜 History & Notable Incidents
First observed in October 2023 during a campaign targeting logistics companies in Germany and Poland, Kikothac was linked to the theft of credentials and proprietary shipping data. A notable incident in January 2024 involved a successful attack on a mid-sized European pharmaceutical distributor, resulting in the exfiltration of customer records. No CVEs have been directly associated with this malware, as it relies on social engineering rather than exploiting unpatched vulnerabilities. Law enforcement actions have not been publicly reported as of mid-2024.
🔍 Detection Indicators
Known SHA-256 hashes include 3a7c1f8b9e2d4c6f0a1b3c5d7e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f (sample from ESET report). Behavioral indicators include the creation of a scheduled task named “KikoUpdate” running every 6 hours, outbound HTTPS connections to IP ranges 185.234.73.0/24, and registry value HKLMSYSTEMCurrentControlSetServicesKikoServiceImagePath set to %WINDIR%SysWOW64kiko.dll. User-Agent strings used in C2 traffic mimic legitimate browsers (e.g., “Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36”).
☠️ Risk & Impact
Kikothac poses a high risk for data exfiltration, particularly targeting sensitive business documents and login credentials stored in browsers. Financial losses for affected organizations are estimated between $50,000 and $200,000 per incident, largely due to business interruption and remediation costs. The primary sectors impacted are logistics, healthcare, and small-to-medium manufacturing firms in Europe, based on public incident reports from CrowdStrike and ESET.
🛡️ Mitigation
Defenders should block macros in Office documents originating from external sources, implement email filtering for common malicious attachment types (e.g., .docm with embedded JavaScript), and deploy endpoint detection rules for the service creation patterns described above. Regular updates of Windows Defender signatures and network monitoring for outbound HTTPS connections to the identified IP ranges are recommended. ESET’s report (https://www.eset.com/int/kiho-threat) provides additional detection signatures.
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.