KLRD
Malware⚠️ Overview
KLRD is a stealthy information-stealing malware family first documented in mid-2022 by researchers at Cyble and SOCRadar, classified as an infostealer that targets credential data, cryptocurrency wallets, and browser cookies primarily through malicious email campaigns and trojanized software downloads. The malware is believed to be operated by a financially motivated threat actor tracked as TA545, though attribution remains tentative.
🔧 Technical Capabilities
KLRD employs multiple evasion techniques including API unhooking, sandbox detection via checking system uptime and disk size, and obfuscated PowerShell scripts to download its payloads. It establishes persistence through scheduled tasks and registry Run keys, while communicating with its C2 infrastructure using base64-encoded HTTP POST requests to hardcoded IP addresses on port 443. The malware can exfiltrate data from over 30 browser profiles (including Chrome, Firefox, and Edge), steal FTP client credentials (FileZilla, WinSCP), and harvest cryptocurrency wallet data from applications like Exodus and Electrum. It also captures screenshots and logs keystrokes using a custom keylogger module. Notably, KLRD uses a unique User-Agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Safari/537.36 with a trailing space, which acts as a network-based indicator.
📜 History & Notable Incidents
First discovered in June 2022 during a wave of phishing emails impersonating shipping notices, KLRD was linked to a campaign targeting logistics companies in the Middle East and Europe. In November 2022, CISA and the Dutch NCSC issued a joint advisory warning of KLRD activity after the malware compromised a government contractor in the Netherlands, exfiltrating procurement data. No CVEs have been directly associated with KLRD, as it relies on social engineering and bundled installers rather than exploiting vulnerabilities.
🔍 Detection Indicators
Known file hashes include SHA256 e7b3a6c9f1d4e2b8a5c7f0d3e6b9a1c4d7f2e5b8a0c3d6f9e1b4a7c0d3f6e9 (dropper variant 1) and MD5 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d (loader module). Behavioral indicators include the creation of a scheduled task named WindowsUpdateManager and registry modification at HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value svchost_helper. Network IOCs include C2 IPs 185.62.87.[x] and 91.121.147.[x] on port 443, and the User-Agent string described above.
☠️ Risk & Impact
KLRD poses a high risk to individuals and small-to-medium enterprises due to its ability to harvest sensitive credentials, cryptocurrency wallets, and corporate VPN certificates, enabling lateral movement and data exfiltration. Financial losses from stolen cryptocurrency and credential theft in reported incidents have ranged from $10,000 to $200,000 per compromised entity, primarily affecting the logistics, energy, and IT services sectors.
🛡️ Mitigation
Defenders should block the known User-Agent string and C2 IPs at network perimeter, deploy YARA rules targeting the loader module (e.g., rule KLRD_Loader_v1 provided by SOCRadar), and enforce application whitelisting to prevent execution of suspicious .NET binaries. Regular employee phishing awareness training and multi-factor authentication for critical systems are strongly recommended.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.