KPOT Stealer

Aliases: Khalesi, Kpot

First seen
2018-05-01 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Last IoC activity
2026-07-21 13:46:55
Profile updated
2026-07-07 13:44:58

Targeted industries: financial-services retail-and-hospitality

Context

KPOT is an information-stealing Trojan horse that can steal information from infected computers. It is distributed through phishing emails and malicious websites. Once executed on a computer, KPOT can steal passwords, credit card numbers, and other personal information.

Detection coverage

  • 3 YARA rules

Detection rules

  • ARKBIRD_SOLG_MAL_Kpot_Oct_2020_1 (yara-rule)
  • CAPE_Kpot (yara-rule)
  • MALPEDIA_Win_Kpot_Stealer_Auto (yara-rule)

Reports & references

  • zdnet.com — Revil Ransomware Gang Acquires Kpot Malware (report)
  • ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
  • spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
  • umbrella.cisco.com — Navigating Cybersecurity During A Pandemic Latest Malware And Threat Actors (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Kpot Stealer (report)
  • blag.nullteilerfrei.de — Use Ghidra To Decrypt Strings Of Kpotstealer Malware (report)
  • news.drweb.com — Show (report)
  • github.com — Kpot.Md (report)
  • isc.sans.edu — 26010 (report)
  • proofpoint.com — New Kpot V20 Stealer Brings Zero Persistence And Memory Features Silently Steal (report)
  • medium.com — Deep Analysis Of Kpot Stealer Fb1D2Be9C5Dd (report)
  • isc.sans.edu — 25934 (report)
  • flashpoint-intel.com — Malware Campaign Targets Jaxx Cryptocurrency Wallet Users (report)
  • blog.ensilo.com — Game Of Trojans Dissecting Khalesi Infostealer Malware (report)

External references