APT32__2020__Release_the_Kraken_Fileless_APT_attack_abuses_Windows_Error_Reporting_service.pdf
ID: cd74c293-5aec-4675-a528-72a36b8198e6
STIX ID: report--cd74c293-5aec-4675-a528-72a36b8198e6
Threat Score
75/100
Uploaded: 2026-08-15
Published Date: 2020-10-08
Last Modified Date: 2020-10-08
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive summary
Malwarebytes describes a targeted fileless APT campaign dubbed "Kraken" that uses a spearphishing Word document with a remote INCLUDEPICTURE template to deliver a malicious macro (modified CactusTorch) which deserializes and loads a .NET DLL (Kraken.dll). The DLL injects embedded shellcode into C:\windows\syswow64\WerFault.exe, performs multiple anti-analysis and VM/debugger checks, resolves APIs dynamically, and its final-stage shellcode fetches a payload from a hard-coded URL (asia-kotoba.net/favicon32.ico); the report includes hashes, hosting domains, download URLs and contextual attribution notes (possible APT32 ties).
