KPOT Stealer Spyware
First observed in 2018, KPOT Stealer is a spyware trojan with similarities to the Agent Tesla malware.
Summary
First observed in 2018, KPOT Stealer is a spyware trojan with similarities to the Agent Tesla malware.
Affected platforms
The following platforms are known to be affected:
Threat details
KPOT Stealer is delivered via malicious macro attachments distributed in spam campaigns. When opened, these macros trigger a Microsoft Equation Editor exploit to download a dropper, which in turn will download KPOT Stealer.
Once installed, KPOT Stealer uses encoded Windows API calls to collect the following information:
- Browser autofill data, cookies and passwords
- Cryptocurrency wallet keys
- Instant messaging, mail and VPN account details
- Windows, Jabber and FTP client credentials
- RDP configuration files
It can also record screen and microphone data, and exfiltrate specific files using parameters sent from a command and control server.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
CVE Vulnerabilities
Last edited: 14 February 2020 2:46 pm