- Status
- Active
- Attribution to this handle
- HIGH 85%
- First observed
- 3 Jul 2026
- Last updated
- 3 Jul 2026
- Operator language
- Portuguese (Brazil), corroborated six ways in the report
- Motivation
- Financial, malware-as-a-service sales rather than targeted intrusion
- Also tracked as
- KAIDO / 0xK41
Note on named actors: n_3_xl is a self-identifying handle, not a real-world identity. The linked report attributes the activity to this handle at HIGH confidence on the evidence it sets out, and says what would raise or lower that figure. No UTA designation was assigned because the attribution clears the bar for naming; the person behind the handle is not established.
Summary
A self-identified Brazilian operator whose stealer-builder configuration names the operator contact, whose support handle's bio names the brand, and whose Quasar-fork RAT resolves to operator-branded infrastructure. Assessed a customer, reseller or affiliate of the separate EvilSoul-Engine developer at MODERATE, not the same person. The attribution is self-attested from the kit's own configuration, which is what holds it at HIGH rather than DEFINITE.
The confidence levels above are the published report's figures. Every claim on this page is a summary of the linked reports, which remain the record.
Targeting
A MaaS vendor; the built stealers target Discord accounts, browser credentials and payment data on whoever the customers deliver them to, with no sector or region of its own.
Targeting is given as region and sector, drawn from the reports. Victim names are deliberately not published here or in the reports.
Reports
Actor identifiers
Artifacts this operator chose or created: handles, channels, operator brands and domains, wallets and the like. Each is printed in a report linked above; the full indicator set, with its caveats, is in each report's IOC feed.
n_3_xl
operator contact named in the stealer-builder's own configuration, a Telegram channel titled KAIDO
@govbrasil
Telegram support handle whose bio names the brand and the maldev handle
0xK41
product brand on the KAIDO line
kaidoo[.]com[.]br
operator-branded domain the KAIDO RAT resolves to
Infrastructure and tooling
- Primary host
- None: the reports anchor this actor on the accounts and artifacts above, not on a host. Hosts belong to the customer operators' pages where the report separates them.
- Tooling
MITRE ATT&CK
44 techniques across 11 tactics, read from the mapping tables of the reports about this actor. Each technique links to where it is mapped. Download this actor's Navigator layer to open the same techniques in ATT&CK Navigator, or the site-wide layer for the whole corpus.
T1027Obfuscated Files or InformationT1036.004Masquerade Task or ServiceT1036.005Match Legitimate Resource Name or LocationT1055Process InjectionT1055.012Process HollowingT1480Execution GuardrailsT1497Virtualization/Sandbox EvasionT1553.005Mark-of-the-Web BypassT1564.001Hidden Files and DirectoriesT1620Reflective Code Loading
Actor profiles and the reports behind them are © Joseph, The Hunter's Ledger, licensed CC BY 4.0: free to use, including commercially, with attribution. All tracked actors.