Kronos
Aliases: Osiris
- First seen
- 2014-01-01 00:00:00
- Malware type
- trojan, credential-stealer, keylogger
- Family
- Malware family
- Last IoC activity
- 2026-07-19 17:16:55
- Profile updated
- 2026-07-07 13:44:41
Targeted industries: financial-services
Context
Kronos malware is a sophisticated banking Trojan that first emerged in 2014. It is designed to target financial institutions and steal sensitive banking information. The malware is primarily spread through phishing campaigns and exploit kits. Once installed on a victim's computer, Kronos can capture login credentials, credit card details, and other personal information by keylogging and form grabbing techniques. It can also bypass security measures such as two-factor authentication. Kronos employs advanced evasion techniques to avoid detection by antivirus software and actively updates itself to evade security patches. It has been known to target a wide range of banking systems and has affected numerous organizations worldwide. The malware continues to evolve, making it a significant threat to online banking security.
Detection coverage
- 2 YARA rules
Detection rules
- CAPE_Kronos (yara-rule)
- MALPEDIA_Win_Kronos_Auto (yara-rule)
Reports & references
- Trend Micro — Gootkit Loaders Updated Tactics And Fileless Delivery Of Cobalt Strike (report)
- intel471.com — Privateloader Malware (report)
- Trend Micro — Operation Black Atlas Endangers In Store Card Payments And Smbs Worldwide Switches Between Blackpos And Other Tools (report)
- zscaler.com — Ares Malware Grandson Kronos Banking Trojan (report)
- f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
- vx-underground.org — Money%20Taker (report)
- Palo Alto Unit 42 — Banking Trojan Techniques (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Kronos (report)
- blog.malwarebytes.com — Inside Kronos Malware P2 (report)
- twitter.com — 1294157781415743488 (report)
- zdnet.com — Security Researcher Malwaretech Pleads Guilty (report)
- blog.morphisec.com — Long Live Osiris Banking Trojan Targets German Ip Addresses (report)
- proofpoint.com — Kronos Reborn (report)
- proofpoint.com — Kronos Banking Trojan Used To Deliver New Point Of Sale Malware (report)
- securityintelligence.com — The Father Of Zeus Kronos Malware Discovered (report)
- therecord.media — Osiris Banking Trojan Shuts Down As New Ares Variant Emerges (report)
- research.checkpoint.com — Deep Dive Upas Kit Vs Kronos (report)
- blog.malwarebytes.com — Inside Kronos Malware (report)
- securonix.com — Securonix Threat Research Kronos Osiris Banking Trojan Attack (report)
- blog.malwarebytes.com — New Looking Sundown Ek Drops Smoke Loader Kronos Banker (report)
- dissectingmalwa.re — Osiris The God Of Afterlifeand Banking Malware (report)