Kerrdown

MITRE
Tipo Malware:
Other
Prima attivita:
Unknown
Ultima attivita:
Unknown
Dettagli:

[Kerrdown](https://attack.mitre.org/software/S0585) is a custom downloader that has been used by [APT32](https://attack.mitre.org/groups/G0050) since at least 2018 to install spyware from a server on the victim's network.(Citation: Amnesty Intl. Ocean Lotus February 2021)(Citation: Unit 42 KerrDown February 2019)

Tecniche Associate (11)
ID ATT&CK Tattiche
T1027.013 Encrypted/Encoded File -
T1027.015 Compression -
T1059.005 Visual Basic -
T1082 System Information Discovery -
T1105 Ingress Tool Transfer -
T1140 Deobfuscate/Decode Files or Information -
T1204.001 Malicious Link -
T1204.002 Malicious File -
T1566.001 Spearphishing Attachment -
T1566.002 Spearphishing Link -
T1574.001 DLL -
Usato da Attori (1)
Metadata
ID: 393
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00