Collecting Malicious Particles from Neutrino Botnets

  • Jakub Souček ESET
  • Jakub Tomanek ESET
  • Peter Kálnai ESET
Keywords: Neutrino Bot, Kasidet, bot, botnet, reverse engineering


Neutrino Bot (also known and detected as Win/Kasidet) is a rapidly changing threat. It first became known around December 2013. It has been actively developed ever since resulting in version 5.4 at the very beginning of 2018. It is being sold for an attractive price to a large variety of cybercriminals.
This paper shows an extensive summary of the history of the bot while focusing on the most recent versions. It presents methods how to analyse Neutrino botnets and provides key findings that have been discovered during the year 2018.


