Skip to main content

KPOT Stealer Spyware

First observed in 2018, KPOT Stealer is a spyware trojan with similarities to the Agent Tesla malware.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

First observed in 2018, KPOT Stealer is a spyware trojan with similarities to the Agent Tesla malware.


Affected platforms

The following platforms are known to be affected:

Threat details

KPOT Stealer is delivered via malicious macro attachments distributed in spam campaigns. When opened, these macros trigger a Microsoft Equation Editor exploit to download a dropper, which in turn will download KPOT Stealer.

Once installed, KPOT Stealer uses encoded Windows API calls to collect the following information:

  • Browser autofill data, cookies and passwords
  • Cryptocurrency wallet keys
  • Instant messaging, mail and VPN account details
  • Windows, Jabber and FTP client credentials
  • RDP configuration files

It can also record screen and microphone data, and exfiltrate specific files using parameters sent from a command and control server.

For further information:


Remediation steps

Type Step

To prevent and detect an infection, ensure that:

  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited emails.
  • All operating systems, anti-virus and other security products are kept up-to-date.
  • Regular anti-virus and security scans are performed on your organisation’s estate.
  • All day-to-day computer activities such as email and internet are performed using non-administrative accounts.
  • Strong password policies are in place.
  • Network, proxy and firewall logs should be monitored for suspicious activity.
  • User accounts accessed from affected devices should be reset on a clean computer.
  • Your organisation adopts a holistic all-round approach to Cyber Security as advocated by the 10 Steps to Cyber Security.


CVE Vulnerabilities

Last edited: 14 February 2020 2:46 pm