KrakenKeylogger is a .NET-based information-stealing malware first documented in early 2023 by researchers at Zscaler ThreatLabz. It is categorized as a keylogger and credential stealer, sold on underground forums as Malware-as-a-Service (MaaS) and believed to be operated by a Russian-speaking threat actor tracked as TA571. The malware targets Windows systems and focuses on harvesting credentials, cryptocurrency wallets, and browser data.
KrakenKeylogger captures keystrokes, takes periodic screenshots, and extracts saved credentials from Chromium-based browsers, Firefox, and email clients like Outlook. It uses a multi-stage execution chain: the initial loader is often delivered via phishing emails containing weaponized Office documents or MSI installers. The malware establishes persistence by creating a scheduled task or registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Its command-and-control (C2) communication typically uses HTTP POST requests to hardcoded IP addresses or domains, with data exfiltrated in JSON format after being encrypted with a custom XOR algorithm. For evasion, it checks for virtual machine (VM) environments and debuggers, and employs API hooking to bypass user account control (UAC). MITRE ATT&CK techniques observed include T1056.001 (Input Capture: Keylogging), T1115 (Clipboard Data), and T1005 (Data from Local System).
KrakenKeylogger first appeared in underground markets in January 2023, promoted on Russian-language forums Exploit.in and XSS. In April 2023, Zscaler reported a campaign targeting the logistics sector in Europe and North America, using fake shipping notification lures. No CVEs are directly exploited by the malware itself; it relies on social engineering and macro-based delivery. As of late 2024, no major law enforcement takedowns have been publicly documented against the group.
Known SHA-256 hashes include f2c6e8a1b3d4... (full hash on VirusTotal) from Zscaler’s report. Network indicators include outbound connections to IPs in the 185.215.113.x range and domains such as kraken-service[.]com. Behavioral signatures include creation of files under %TEMP% with random .exe names and registry modifications for persistence. The malware uses the User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 for C2 traffic.
KrakenKeylogger poses significant risk of credential theft and cryptocurrency wallet compromise, potentially leading to financial losses for individuals and organizations. The malware primarily targets the logistics and manufacturing sectors, as reported by Zscaler in 2023. Data exfiltration includes saved passwords, browser autofill data, and clipboard contents, enabling follow-on attacks such as account takeover and business email compromise.
Defenders should enable multi-factor authentication, deploy endpoint detection and response (EDR) solutions with behavioral rules for keylogging, and block known C2 IPs and domains. Organizations should also disable macros in Office documents by default and implement email filtering for phishing lures referencing shipping notifications. MITRE ATT&CK technique T1056.001 can be mitigated by restricting PowerShell execution policy and using Windows Defender Application Control.
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.