Kardon Loader

First seen
2023-04-25 00:00:00
Malware type
downloader, loader, credential-stealer
Family
Malware family
Profile updated
2026-07-07 15:08:05

Targeted industries: financial-services

Context

According to ASERT, Kardon Loader is a fully featured downloader, enabling the download and installation of other malware, eg. banking trojans/credential theft etc.This malware has been on sale by an actor under the username Yattaze, starting in late April. The actor offers the sale of the malware as a standalone build with charges for each additional rebuild, or the ability to set up a botshop in which case any customer can establish their own operation and further sell access to a new customer base.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Kardonloader (report)
  • engineering.salesforce.com — Kardon Loader Malware Analysis Adaaaab42Bab (report)
  • asert.arbornetworks.com — Kardon Loader Looks For Beta Testers (report)

External references