logo

APT32__2020__Release_the_Kraken_Fileless_APT_attack_abuses_Windows_Error_Reporting_service.pdf

ID: cd74c293-5aec-4675-a528-72a36b8198e6

STIX ID: report--cd74c293-5aec-4675-a528-72a36b8198e6

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2020-10-08

Last Modified Date: 2020-10-08

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive summary Malwarebytes describes a targeted fileless APT campaign dubbed "Kraken" that uses a spearphishing Word document with a remote INCLUDEPICTURE template to deliver a malicious macro (modified CactusTorch) which deserializes and loads a .NET DLL (Kraken.dll). The DLL injects embedded shellcode into C:\windows\syswow64\WerFault.exe, performs multiple anti-analysis and VM/debugger checks, resolves APIs dynamically, and its final-stage shellcode fetches a payload from a hard-coded URL (asia-kotoba.net/favicon32.ico); the report includes hashes, hosting domains, download URLs and contextual attribution notes (possible APT32 ties).