Description
[Kerrdown](https://attack.mitre.org/software/S0585) is a custom downloader that has been used by [APT32](https://attack.mitre.org/groups/G0050) since at least 2018 to install spyware from a server on the victim's network.(Citation: Amnesty Intl. Ocean Lotus February 2021)(Citation: Unit 42 KerrDown February 2019)
External References
Techniques Used by This Malware
- T1027.013 — Encrypted/Encoded File
- T1027.015 — Compression
- T1059.005 — Visual Basic
- T1082 — System Information Discovery
- T1105 — Ingress Tool Transfer
- T1140 — Deobfuscate/Decode Files or Information
- T1204.001 — Malicious Link
- T1204.002 — Malicious File
- T1566.001 — Spearphishing Attachment
- T1566.002 — Spearphishing Link
- T1574.001 — DLL