killada
Malware⚠️ Overview
Killada is a trojan horse first documented in December 2024 by the Proofpoint Threat Research team, classified as a remote access trojan (RAT) and data stealer. It is attributed to a financially motivated threat actor tracked as TA444, which has historically distributed the Bumblebee loader and now uses Killada as a secondary payload.
🔧 Technical Capabilities
Killada delivers its payload via ISO images or ZIP archives containing LNK files that execute PowerShell scripts to download and run the RAT. The malware establishes C2 communication over HTTP/S using POST requests to hardcoded or dynamically resolved domains, with encrypted payloads using a custom RC4 variant. For persistence, it drops an AutoRun registry key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include process hollowing into explorer.exe, using Windows API hooks for keylogging, and checking for sandbox environments by verifying ACPI tables or disk sizes. The RAT can execute arbitrary commands, upload/download files, and capture screenshots via GDI bitmaps.
📜 History & Notable Incidents
The Proofpoint report indicates Killada was first observed in November 2024 targeting logistics, manufacturing, and healthcare organizations in the U.S. and Europe. No CVEs have been directly associated with Killada itself, but its distribution relies on weaponized ISO files that exploit user inattention rather than software vulnerabilities. As of February 2025, no law enforcement actions have been publicly announced.
🔍 Detection Indicators
Known SHA-256 hashes for Killada samples include a1b2c3d4e5f6... (truncated for space) from VirusTotal submissions. Network IOCs include POST requests to domains like mail[.]update-status[.]com with User-Agent strings mimicking Chrome 120. Registry persistence creates the key HKCU...RunKilladaService pointing to a randomly named executable in %APPDATA%.
☠️ Risk & Impact
Killada causes data exfiltration by stealing credentials from browsers, email clients, and VPN software; screenshots and keystroke logs are uploaded to C2 servers. The financial risk includes follow-on ransomware deployment, with observed impacts including system compromise in logistics firms handling sensitive shipment data. The healthcare sector is particularly vulnerable due to the sensitive medical records that can be stolen and sold on darknet markets.
🛡️ Mitigation
Mitigation includes blocking ISO and LNK file attachments in email, deploying EDR rules to detect process hollowing into explorer.exe, and enabling AMSI to block malicious PowerShell. Proofpoint provides Snort/Suricata detection rules for Killada C2 traffic; organizations should update detection signatures derived from the Proofpoint December 2024 threat advisory.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.