Skip to main content

Boteraser | Website and Server Security Solutions

KrakenKeylogger

Keylogger

⚠️ Overview

KrakenKeylogger is a .NET-based information-stealing malware first documented in early 2023 by researchers at Zscaler ThreatLabz. It is categorized as a keylogger and credential stealer, sold on underground forums as Malware-as-a-Service (MaaS) and believed to be operated by a Russian-speaking threat actor tracked as TA571. The malware targets Windows systems and focuses on harvesting credentials, cryptocurrency wallets, and browser data.

🔧 Technical Capabilities

KrakenKeylogger captures keystrokes, takes periodic screenshots, and extracts saved credentials from Chromium-based browsers, Firefox, and email clients like Outlook. It uses a multi-stage execution chain: the initial loader is often delivered via phishing emails containing weaponized Office documents or MSI installers. The malware establishes persistence by creating a scheduled task or registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Its command-and-control (C2) communication typically uses HTTP POST requests to hardcoded IP addresses or domains, with data exfiltrated in JSON format after being encrypted with a custom XOR algorithm. For evasion, it checks for virtual machine (VM) environments and debuggers, and employs API hooking to bypass user account control (UAC). MITRE ATT&CK techniques observed include T1056.001 (Input Capture: Keylogging), T1115 (Clipboard Data), and T1005 (Data from Local System).

📜 History & Notable Incidents

KrakenKeylogger first appeared in underground markets in January 2023, promoted on Russian-language forums Exploit.in and XSS. In April 2023, Zscaler reported a campaign targeting the logistics sector in Europe and North America, using fake shipping notification lures. No CVEs are directly exploited by the malware itself; it relies on social engineering and macro-based delivery. As of late 2024, no major law enforcement takedowns have been publicly documented against the group.

🔍 Detection Indicators

Known SHA-256 hashes include f2c6e8a1b3d4... (full hash on VirusTotal) from Zscaler’s report. Network indicators include outbound connections to IPs in the 185.215.113.x range and domains such as kraken-service[.]com. Behavioral signatures include creation of files under %TEMP% with random .exe names and registry modifications for persistence. The malware uses the User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 for C2 traffic.

☠️ Risk & Impact

KrakenKeylogger poses significant risk of credential theft and cryptocurrency wallet compromise, potentially leading to financial losses for individuals and organizations. The malware primarily targets the logistics and manufacturing sectors, as reported by Zscaler in 2023. Data exfiltration includes saved passwords, browser autofill data, and clipboard contents, enabling follow-on attacks such as account takeover and business email compromise.

🛡️ Mitigation

Defenders should enable multi-factor authentication, deploy endpoint detection and response (EDR) solutions with behavioral rules for keylogging, and block known C2 IPs and domains. Organizations should also disable macros in Office documents by default and implement email filtering for phishing lures referencing shipping notifications. MITRE ATT&CK technique T1056.001 can be mitigated by restricting PowerShell execution policy and using Windows Defender Application Control.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.