Neutrino
Aliases: Kasidet
- Malware type
- botnet, exploit-kit
- Family
- Malware family
- Last IoC activity
- 2026-07-21 04:34:27
- Profile updated
- 2026-07-07 14:59:00
Targeted industries: financial-services technology-and-telecommunications
Context
Neutrino, also known as Kasidet, is a malware family known for its exploit kit functionality, often used in cyber attacks against financial institutions and technology sectors. It leverages various vulnerabilities to infect systems and facilitate further malicious activities.
Detection coverage
- 2 YARA rules
Detection rules
- MALPEDIA_Win_Neutrino_Pos_Auto (yara-rule)
- MALPEDIA_Win_Graphical_Neutrino_Auto (yara-rule)
Related threat objects
- Kasidet (malware)
- Neutrino (infrastructure)
Reports & references
- virusbulletin.com — Vb2019 Paper Rich Headers Leveraging Mysterious Artifact Pe Format (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Neutrino (report)
- malware.dontneedcoffee.com — Neutrino Bot Aka Kasidet (report)
- blog.malwarebytes.com — New Neutrino Bot Comes In A Protective Loader (report)
- Trend Micro — Credit Card Scraping Kasidet Builder Leads To Spike In Detections (report)
- securityblog.switch.ch — 94 Ch Li Domain Names Hijacked And Used For Drive By (report)
- journal.cecyf.fr — 22 (report)
- web.archive.org — Finding Neutrino (report)
- zscaler.com — Malicious Office Files Dropping Kasidet And Dridex (report)
- blog.ptsecurity.com — Finding Neutrino (report)
- malwarebreakdown.com — Shadow Server Domains Leads To Rig Exploit Kit Dropping Smoke Loader Which Downloads Neutrino Bot Aka Kasidet (report)
- blog.malwarebytes.com — Inside Neutrino Botnet Builder (report)
- peppermalware.com — Analysis Of Neutrino Bot Sample 2018 08 27 (report)
- blog.malwarebytes.com — Post Holiday Spam Campaign Delivers Neutrino Bot (report)