Kronos

Aliases: Osiris

First seen
2014-01-01 00:00:00
Malware type
trojan, credential-stealer, keylogger
Family
Malware family
Last IoC activity
2026-07-19 17:16:55
Profile updated
2026-07-07 13:44:41

Targeted industries: financial-services

Context

Kronos malware is a sophisticated banking Trojan that first emerged in 2014. It is designed to target financial institutions and steal sensitive banking information. The malware is primarily spread through phishing campaigns and exploit kits. Once installed on a victim's computer, Kronos can capture login credentials, credit card details, and other personal information by keylogging and form grabbing techniques. It can also bypass security measures such as two-factor authentication. Kronos employs advanced evasion techniques to avoid detection by antivirus software and actively updates itself to evade security patches. It has been known to target a wide range of banking systems and has affected numerous organizations worldwide. The malware continues to evolve, making it a significant threat to online banking security.

Detection coverage

  • 2 YARA rules

Detection rules

  • CAPE_Kronos (yara-rule)
  • MALPEDIA_Win_Kronos_Auto (yara-rule)

Reports & references

  • Trend Micro — Gootkit Loaders Updated Tactics And Fileless Delivery Of Cobalt Strike (report)
  • intel471.com — Privateloader Malware (report)
  • Trend Micro — Operation Black Atlas Endangers In Store Card Payments And Smbs Worldwide Switches Between Blackpos And Other Tools (report)
  • zscaler.com — Ares Malware Grandson Kronos Banking Trojan (report)
  • f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
  • vx-underground.org — Money%20Taker (report)
  • Palo Alto Unit 42 — Banking Trojan Techniques (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Kronos (report)
  • blog.malwarebytes.com — Inside Kronos Malware P2 (report)
  • twitter.com — 1294157781415743488 (report)
  • zdnet.com — Security Researcher Malwaretech Pleads Guilty (report)
  • blog.morphisec.com — Long Live Osiris Banking Trojan Targets German Ip Addresses (report)
  • proofpoint.com — Kronos Reborn (report)
  • proofpoint.com — Kronos Banking Trojan Used To Deliver New Point Of Sale Malware (report)
  • securityintelligence.com — The Father Of Zeus Kronos Malware Discovered (report)
  • therecord.media — Osiris Banking Trojan Shuts Down As New Ares Variant Emerges (report)
  • research.checkpoint.com — Deep Dive Upas Kit Vs Kronos (report)
  • blog.malwarebytes.com — Inside Kronos Malware (report)
  • securonix.com — Securonix Threat Research Kronos Osiris Banking Trojan Attack (report)
  • blog.malwarebytes.com — New Looking Sundown Ek Drops Smoke Loader Kronos Banker (report)
  • dissectingmalwa.re — Osiris The God Of Afterlifeand Banking Malware (report)

External references