KerrDown is a Trojan downloader whose usage and development are attributed to the OceanLotus hackers, also known as APT32. Their activities are focused on the Asia-Pacific region, and the KerrDown Trojan downloader appears to have been used against a plethora of targets based in Vietnam. The payload is delivered with the use of spear-phishing emails packed with a corrupted file attachment – either a Microsoft Office document or a RAR archive.
The Vietnamese KerrDown campaign appeared to focus on delivering a secondary payload, which was executed from the computer's memory directly – a common strategy that malware creators use to reduce the footprint their activities leave behind. In this particular operation, the OceanLotus APT hackers delivered a copy of the Cobalt Strike framework, a penetration testing tool that is being misused by cybercriminals worldwide.
The OceanLotus hackers have been the leading threat in the Asia-Pacific region for many years, and it certainly seems like they are not planning to give up the top spot just yet. While they still use outdated payloads like the Cobalt Strike framework, they are clearly experimenting with new Trojans to exploit weaknesses in the networks of their targets. The KerrDown Downloader is just one of the latest projects used to enhance OceanLotus' campaigns.
Use SpyHunter to Detect and Remove PC Threats
If you are concerned that malware or PC threats similar to KerrDown may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.
Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.