Malicious Office Files Dropping Kasidet And Dridex
ID: 79f6339e-578a-5303-a139-76d3d1e0f34d
STIX ID: report--79f6339e-578a-5303-a139-76d3d1e0f34d
Feed Name: Zscaler Security Research Blog
Threat Score
**Executive summary:** This report analyzes a Kasidet information-stealer campaign delivered via malicious Office documents; the variant performs POS memory scraping and browser hooking to exfiltrate credentials and payment data, includes anti-VM/Wine checks, uses hardcoded C2 URLs and custom HTTP headers with hidden commands in HTML comments, and supports plugin downloads and remote commands.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
