Koadic
MITRE ATT&CK: S0250 View on attack.mitre.org
Aliases: Koadic
- First seen
- 2017-07-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 33 (30 malicious)
- Last IoC activity
- 2026-09-02 01:40:50
- Profile updated
- 2026-07-07 12:42:41
Targeted industries: government-and-public-sector
Context
Koadic is a Windows post-exploitation framework and penetration testing tool that is publicly available on GitHub. Koadic has several options for staging payloads and creating implants, and performs most of its operations using Windows Script Host.
Recent IoC activity
30 malicious indicators in Maltiverse are attributed to Koadic (S0250). The 20 most recently updated:
Detection coverage
- 2 YARA rules
- 798 Sigma rules
Malware & tools used
- System Network Configuration Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Visual Basic (attack-pattern)
- Mshta (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Regsvr32 (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Hidden Window (attack-pattern)
- Security Account Manager (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Web Protocols (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- PowerShell (attack-pattern)
- Clipboard Data (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Network Service Discovery (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Windows Command Shell (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- NTDS (attack-pattern)
- Service Execution (attack-pattern)
- Data from Local System (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Network Share Discovery (attack-pattern)
Used by threat actors
- APT28 (threat-actor)
- LazyScripter (threat-actor)
- MuddyWater (threat-actor)
- Sidewinder (threat-actor)
Detection rules
- MALPEDIA_Win_Koadic_Auto (yara-rule)
- DITEKSHEN_MALWARE_JS_Koadicjs (yara-rule)
Reports & references
- secureworks.com — Cobalt Trinity (report)
- secureworks.com — Cobalt Ulster (report)
- secureworks.com — Gold Drake (report)
- researchcenter.paloaltonetworks.com — Unit42 Sofacy Groups Parallel Attacks (report)
- web.archive.org — Lazyscripter (report)
- cdn-cybersecurity.att.com — Global Perspective Of The Sidewinder Apt (report)
- secureworks.com — Gold Drake (report)
- labs.bitdefender.com — 5 Times More Coronavirus Themed Malware Reports During March (report)
- resources.malwarebytes.com — Lazyscripter (report)
- secureworks.com — Cobalt Ulster (report)
- jsac.jpcert.or.jp — Jsac2024 1 9 Takeda Furukawa En (report)
- prodaft.com — Silverfish Tlpwhite (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Koadic (report)
- github.com — Koadic (report)
- blog.tofile.dev — Koadic Jarm (report)
- MITRE ATT&CK — S0250 (report)
- github.com — Koadic (report)