KPOT Stealer
Aliases: Khalesi, Kpot
- First seen
- 2018-05-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-21 13:46:55
- Profile updated
- 2026-07-07 13:44:58
Targeted industries: financial-services retail-and-hospitality
Context
KPOT is an information-stealing Trojan horse that can steal information from infected computers. It is distributed through phishing emails and malicious websites. Once executed on a computer, KPOT can steal passwords, credit card numbers, and other personal information.
Detection coverage
- 3 YARA rules
Detection rules
- ARKBIRD_SOLG_MAL_Kpot_Oct_2020_1 (yara-rule)
- CAPE_Kpot (yara-rule)
- MALPEDIA_Win_Kpot_Stealer_Auto (yara-rule)
Reports & references
- zdnet.com — Revil Ransomware Gang Acquires Kpot Malware (report)
- ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
- spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
- umbrella.cisco.com — Navigating Cybersecurity During A Pandemic Latest Malware And Threat Actors (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Kpot Stealer (report)
- blag.nullteilerfrei.de — Use Ghidra To Decrypt Strings Of Kpotstealer Malware (report)
- news.drweb.com — Show (report)
- github.com — Kpot.Md (report)
- isc.sans.edu — 26010 (report)
- proofpoint.com — New Kpot V20 Stealer Brings Zero Persistence And Memory Features Silently Steal (report)
- medium.com — Deep Analysis Of Kpot Stealer Fb1D2Be9C5Dd (report)
- isc.sans.edu — 25934 (report)
- flashpoint-intel.com — Malware Campaign Targets Jaxx Cryptocurrency Wallet Users (report)
- blog.ensilo.com — Game Of Trojans Dissecting Khalesi Infostealer Malware (report)