The operators of the REvil ransomware acquired the source code of the KPOT malware in an auction held on a hacking forum last month. The sale took place after the creator of the KPOT malware decided to put the code up for auction.
Security researcher Pancak3 told ZDNet last month that the sale was organized as a public auction on a private underground hacking forum for Russian-speaking cybercriminals. According to Pancak3, the only bidder was UNKN, a known member of the REvil/Sodinokibi ransomware gang. UNKN paid the initial asking price of $6,500, while other forum members declined to participate, noting that the asking price had been increased sharply. The operators of the REvil ransomware received the source code for KPOT 2.0, which is the latest version of the KPOT malware.

Discovered in 2018, KPOT is a classic infostealer that can extract and steal passwords from various applications running on infected computers. This includes web browsers, email clients, VPNs, RDP services, FTP applications, crypto , and software , according to a report released by Proofpoint in 2019.
Pancak3, who discovered the KPOT auction in mid-October, told ZDNet that he believes the REvil gang purchased KPOT to further develop and evolve it, as well as to add it to their “arsenal” for future attacks on corporate networks.

Unlike UNKN and the Revil gang, many other forum members described the KPOT code as “overpriced.” The Revil gang member recently gave an interview to a Russian YouTube, claiming that the ransomware gang makes more than $100 million a year. UNKN also claimed that the gang fears potential assassinations more than law enforcement response and action.
