DeadlyKiss APT
ID: 9df1f711-ccd0-460a-97b6-302d00f35bbf
STIX ID: report--9df1f711-ccd0-460a-97b6-302d00f35bbf
Threat Score
88/100
Uploaded: 2026-08-11
Published Date: 2019-09-24
Last Modified Date: 2019-09-24
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive summary
This report details the discovery and technical analysis of "DeadlyKiss", an advanced, highly obfuscated C++ loader/backdoor observed since 2016 that targets Internet Service Providers and related organizations; it uses AES-256 encrypted payloads, flexible persistence (COM in-process or system service, scheduled tasks), timed HTTP C2 communications, and strong evasion techniques, and includes IoCs (domains, IP, hashes) and a detection rule.
