Kardon Loader
- First seen
- 2023-04-25 00:00:00
- Malware type
- downloader, loader, credential-stealer
- Family
- Malware family
- Profile updated
- 2026-07-07 15:08:05
Targeted industries: financial-services
Context
According to ASERT, Kardon Loader is a fully featured downloader, enabling the download and installation of other malware, eg. banking trojans/credential theft etc.This malware has been on sale by an actor under the username Yattaze, starting in late April. The actor offers the sale of the malware as a standalone build with charges for each additional rebuild, or the ability to set up a botshop in which case any customer can establish their own operation and further sell access to a new customer base.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Kardonloader (report)
- engineering.salesforce.com — Kardon Loader Malware Analysis Adaaaab42Bab (report)
- asert.arbornetworks.com — Kardon Loader Looks For Beta Testers (report)