Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Kraken was a Go-based botnet targeting Windows that ZeroFox publicly described on February 16, 2022. In observations from late 2021, it spread through SmokeLoader, established logon persistence, and could run commands, capture screenshots, deliver other malware, and steal cryptocurrency wallets. Those findings describe activity observed at the time; they do not establish that Kraken remains active today.

What was the Kraken botnet?

Kraken was a Windows botnet whose malware was written in Go, also called Golang. ZeroFox described it as previously unknown when it disclosed the botnet in February 2022. It is distinct from a separate botnet that used the Kraken name in 2008; the shared name does not indicate that the two operations were connected.

The available reporting captures an emerging operation, not a final account of its scale or purpose. SecurityWeek reported on February 18, 2022, that Kraken was adding hundreds of systems with each newly deployed command-and-control (C2) server. That is a report about observed growth, not a verified lifetime victim total.

How did Kraken spread and persist on Windows?

Delivery through SmokeLoader

Initially, SmokeLoader delivered self-extracting RAR archives containing an UPX-packed Kraken binary, RedLine Stealer, and a deletion utility. In later versions, SmokeLoader downloaded Kraken directly, and the malware was additionally protected with Themida. The changing packaging suggests the delivery method evolved; the evidence does not establish a single delivery format for every infection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Installation and logon persistence

During installation, Kraken copied itself into %AppData%Microsoft, added a Windows Run registry entry so it could start at logon, and used the Windows attrib command to hide the copied executable. It also excluded that directory from Microsoft Defender scanning. These changes were intended to help the malware remain on an infected system and avoid routine visibility.

What could Kraken do after infection?

Observed builds combined host discovery, remote control, payload delivery, and data theft. They could:

  • Send host details to the operator, including hostname, username, CPU and GPU details, operating-system information, and a build ID.
  • Download and execute files, and run Windows shell commands.
  • Take screenshots immediately or when requested.
  • Steal cryptocurrency wallets associated with Zcash, Armory, Bytecoin, Electrum, Ethereum, Exodus, Guarda, Atomic, and Jaxx.

Some builds briefly contained an SSH brute-force feature. ZeroFox reported no evidence that it was used, and the feature was later removed. Its presence in a build should not be confused with evidence of a successful campaign using it.

How did the operator manage victims and payloads?

The original Kraken Panel provided basic statistics and payload management. A redesigned Anubis Panel added command history and victim information, along with the ability to target a particular victim, a group, an external IP address, or a geographic area.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ZeroFox monitoring of commands sent from October through December 2021 found the operator focused on delivering information stealers, especially RedLine Stealer. Later observations also included other information stealers and cryptocurrency miners. ZeroFox summarized its findings this way: “Monitoring commands sent to Kraken victims from October 2021 through December 2021 revealed that the operator had focused entirely on pushing information stealers – specifically RedLine Stealer. It is currently unknown what the operator intends to do with the stolen credentials that have been collected or what the end goal is for creating this new botnet.”

What is known about Kraken’s origin and earnings?

ZeroFox found early Kraken code on GitHub dated October 10, 2021, before the observed binaries appeared. The researchers could not determine whether the account belonged to the operator or whether the code had been reused, so the GitHub appearance does not identify who created or ran the botnet.

ZeroFox Intelligence estimated observed activity at approximately USD 3,000 per month in 2022. This was an estimate, not audited revenue or a verified financial statement; the reporting does not establish how much the operators ultimately earned.

How can organizations reduce the risk of Kraken-like infections?

ZeroFox recommended general security controls rather than reporting product tests or comparative effectiveness results. For Windows users and administrators, its guidance translates into these practical checks:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Keep antivirus and intrusion-detection software current.
  • Use two-factor authentication on accounts, particularly where stolen credentials could grant access to email, administration, or financial services.
  • Maintain scheduled backups stored off-site, and check their integrity so they can be relied on during recovery.
  • Treat unsolicited attachments and suspicious links cautiously; do not open them simply because they arrive in a familiar-looking message.
  • Monitor administrative actions and review network logs for suspicious outbound connections.

These controls address different stages of an incident: cautious handling can reduce exposure to malicious delivery, monitoring can help surface suspicious behavior, and off-site backups support recovery. No single control is a guarantee against infection.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the available reporting does—and does not—establish

The public account rests on ZeroFox’s observations of activity in late 2021 and reporting published in February 2022. It documents a Go-based Windows botnet, its observed delivery and capabilities, and its operators’ emphasis on information stealers. It does not establish Kraken’s current activity, a final victim count, the operators’ identity, or their ultimate intent.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.