logo

Malicious Office Files Dropping Kasidet And Dridex

ID: 79f6339e-578a-5303-a139-76d3d1e0f34d

STIX ID: report--79f6339e-578a-5303-a139-76d3d1e0f34d

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive summary:** This report analyzes a Kasidet information-stealer campaign delivered via malicious Office documents; the variant performs POS memory scraping and browser hooking to exfiltrate credentials and payment data, includes anti-VM/Wine checks, uses hardcoded C2 URLs and custom HTTP headers with hidden commands in HTML comments, and supports plugin downloads and remote commands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.