SYMBOLCOMMON_NAMEaka. SYNONYMS
win.kamasers (Back to overview)

Kamasers

VTCollection    

Kamasers is a DDOS botnet. The bot has backdoor capabilities as it connects to an attacker controller C2 server. This allows it to download files, receive commands, and execute files, allowing it to perform HTTP and DNS flooding attacks. The bot is also used to access sensitive files.

The bot has been seen to be communicating with third-party platforms such as Telegram, Discord, and GitHub, using these platforms as backup C2 servers.

References
2026-03-25 ⋅ ANY.RUN ⋅ Achmad Adhikara, GridGuardGhoul
Kamasers Analysis: A Multi-Vector DDoS Botnet Targeting Organizations Worldwide
Kamasers
2025-09-26 ⋅ abuse.ch ⋅ abuse.ch
Twitter Post
Kamasers
Yara Rules
[TLP:WHITE] win_kamasers_auto (20260917 | Detects win.kamasers.)
rule win_kamasers_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.kamasers."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.kamasers"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 83f81f 7732 e9???????? 6a00 6a00 6a00 6a00 }
            // n = 7, score = 100
            //   83f81f               | cmp                 eax, 0x1f
            //   7732                 | ja                  0x34
            //   e9????????           |                     
            //   6a00                 | push                0
            //   6a00                 | push                0
            //   6a00                 | push                0
            //   6a00                 | push                0

        $sequence_1 = { e8???????? 6a05 e8???????? 6a06 c705????????feffff7f e8???????? 6a00 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   6a05                 | push                5
            //   e8????????           |                     
            //   6a06                 | push                6
            //   c705????????feffff7f     |     
            //   e8????????           |                     
            //   6a00                 | push                0

        $sequence_2 = { 8b4da4 8d45d4 8b55a0 c745fc01000000 837de80f 0f4745d4 8b12 }
            // n = 7, score = 100
            //   8b4da4               | mov                 ecx, dword ptr [ebp - 0x5c]
            //   8d45d4               | lea                 eax, [ebp - 0x2c]
            //   8b55a0               | mov                 edx, dword ptr [ebp - 0x60]
            //   c745fc01000000       | mov                 dword ptr [ebp - 4], 1
            //   837de80f             | cmp                 dword ptr [ebp - 0x18], 0xf
            //   0f4745d4             | cmova               eax, dword ptr [ebp - 0x2c]
            //   8b12                 | mov                 edx, dword ptr [edx]

        $sequence_3 = { 8d4594 0f474594 6a00 6800800000 50 6a00 8d45ac }
            // n = 7, score = 100
            //   8d4594               | lea                 eax, [ebp - 0x6c]
            //   0f474594             | cmova               eax, dword ptr [ebp - 0x6c]
            //   6a00                 | push                0
            //   6800800000           | push                0x8000
            //   50                   | push                eax
            //   6a00                 | push                0
            //   8d45ac               | lea                 eax, [ebp - 0x54]

        $sequence_4 = { ba02000000 85c0 8b45c8 0f44f2 }
            // n = 4, score = 100
            //   ba02000000           | mov                 edx, 2
            //   85c0                 | test                eax, eax
            //   8b45c8               | mov                 eax, dword ptr [ebp - 0x38]
            //   0f44f2               | cmove               esi, edx

        $sequence_5 = { 668901 884102 0fb602 343f 8801 0fb64201 343f }
            // n = 7, score = 100
            //   668901               | mov                 word ptr [ecx], ax
            //   884102               | mov                 byte ptr [ecx + 2], al
            //   0fb602               | movzx               eax, byte ptr [edx]
            //   343f                 | xor                 al, 0x3f
            //   8801                 | mov                 byte ptr [ecx], al
            //   0fb64201             | movzx               eax, byte ptr [edx + 1]
            //   343f                 | xor                 al, 0x3f

        $sequence_6 = { c745fc0e000000 81c900080000 898d70feffff 6810270000 6a01 8d458c c645fc10 }
            // n = 7, score = 100
            //   c745fc0e000000       | mov                 dword ptr [ebp - 4], 0xe
            //   81c900080000         | or                  ecx, 0x800
            //   898d70feffff         | mov                 dword ptr [ebp - 0x190], ecx
            //   6810270000           | push                0x2710
            //   6a01                 | push                1
            //   8d458c               | lea                 eax, [ebp - 0x74]
            //   c645fc10             | mov                 byte ptr [ebp - 4], 0x10

        $sequence_7 = { e8???????? 8d8d04d9ffff c645fc02 83bdf4ecffff07 8d85e0ecffff 51 0f4785e0ecffff }
            // n = 7, score = 100
            //   e8????????           |                     
            //   8d8d04d9ffff         | lea                 ecx, [ebp - 0x26fc]
            //   c645fc02             | mov                 byte ptr [ebp - 4], 2
            //   83bdf4ecffff07       | cmp                 dword ptr [ebp - 0x130c], 7
            //   8d85e0ecffff         | lea                 eax, [ebp - 0x1320]
            //   51                   | push                ecx
            //   0f4785e0ecffff       | cmova               eax, dword ptr [ebp - 0x1320]

        $sequence_8 = { 50 8d45f4 64a300000000 8bf9 89bd34feffff 89bd6cfeffff 89bd6cfeffff }
            // n = 7, score = 100
            //   50                   | push                eax
            //   8d45f4               | lea                 eax, [ebp - 0xc]
            //   64a300000000         | mov                 dword ptr fs:[0], eax
            //   8bf9                 | mov                 edi, ecx
            //   89bd34feffff         | mov                 dword ptr [ebp - 0x1cc], edi
            //   89bd6cfeffff         | mov                 dword ptr [ebp - 0x194], edi
            //   89bd6cfeffff         | mov                 dword ptr [ebp - 0x194], edi

        $sequence_9 = { 83c408 c785f8fdffff11000000 81ce00020000 898dfcfdffff 33d2 0f1100 }
            // n = 6, score = 100
            //   83c408               | add                 esp, 8
            //   c785f8fdffff11000000     | mov    dword ptr [ebp - 0x208], 0x11
            //   81ce00020000         | or                  esi, 0x200
            //   898dfcfdffff         | mov                 dword ptr [ebp - 0x204], ecx
            //   33d2                 | xor                 edx, edx
            //   0f1100               | movups              xmmword ptr [eax], xmm0

    condition:
        7 of them and filesize < 906240
}
Download all Yara Rules