🚨 OSINT UPDATE: I discovered KAIDO RAT v2.2 and just located a recent
ANY.RUN analysis potentially linked to it
Thread 1/8
Since I publicly exposed KAIDO RAT v2.2 on March 28, 2026, I have continued monitoring the infrastructure of the [[KAIDO]] PROJECT MaaS.
Today I located a recent analysis on
ANY.RUN that may have a strong connection to the malware I discovered. Two public submissions (early April 2026) classify it as Malicious activity – Loader with the classic fake Banco do Brasil boleto vector.
Primary sources (public analyses I identified):
• Main analysis (SHA256: 61964D6A9BEB6EF861763B7F974A830AF777E1AED16DFFDFD06B70ADFD14B033):
app.any.run/tasks/266fce5c-a…
• Complementary analysis (/bt/ bb_dropper.bat):
app.any.run/tasks/e6885ad4-0…
Thread 2/8
Chain of Infection observed in the analysis I found:
1Victim clicks on the lure “Boleto_BB_2aVia.pdf” → Microsoft Edge opens UNC path:
\free.kaido.sh@80\bt\Boleto_BB_2aVia.pdf
2Activates the WebClient service (svchost.exe -s WebClient).
3Mounts WebDAV share (port 80).
4Executes bb_dropper.bat via cmd.exe.
Thread 3/8
The dropper downloads the packed payload to:
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\TfsStore\Tfs_DAV\
Behaviors observed in the analysis:
• Full WebDAV abuse DLL preloading
• IsDebuggerPresent (anti-debug)
• Sandbox checks (disk, IP, system language)
• .lnk creation for persistence
• IP: 185.208.158.27 (Seychelles, ASN AS42624)
Thread 4/8
Correlation I established with KAIDO RAT v2.2
This recent analysis I found points exactly to the initial infection vector of the malware I discovered.
Same root domain (
kaido.sh registered on 03/16/2026 via Njalla), same N3X/[[KAIDO]] PROJECT MaaS channel, and same Kitsune branding.
Loader → KAIDO RAT v2.2 (full C2 panel, 10 elite evasion modules, 11 stealers 7 PIX/banking modules) → possible escalation to KAIDO Ransomware.
Thread 5/8
IOCs I extracted from this analysis:
• Domain:
free.kaido.sh (and all *.kaido.sh)
• IP: 185.208.158.27
• Key file: bb_dropper.bat
• Sensitive path: TfsStore\Tfs_DAV\
• Example hash: 61964D6A9BEB6EF861763B7F974A830AF777E1AED16DFFDFD06B70ADFD14B033
Block these NOW.
Thread 6/8
Risk assessment: HIGH and actively used against Brazilian PIX and boleto users.
A single click on an unsolicited “2nd copy of boleto” can deliver full device control PIX theft possible ransomware.
Thread 7/8
Direct recommendations from my investigation:
• Immediately block *.kaido.sh 185.208.158.27
• Monitor WebClient UNC paths with
@80
• EDR alerts for Tfs_DAV and bb_dropper.bat
• Golden rule: Never click on boleto links — always access the bank’s official website directly
Thread 8/8
This is the continuation of the research that revealed KAIDO RAT. I found this recent analysis on
ANY.RUN and immediately correlated it.
Threat confirmed and active. Share to help protect the community.
More updates coming soon.
#KaidoRAT #CyberSecurity #ThreatIntel #Malware #OSINT #PIX #BankingTrojan #MaaS #InfoSec #Ransomware
@anyrun_app @BancodoBrasil