Conficker is a self-propagating Windows worm that infected millions of systems globally. Its primary infection vector was exploitation of CVE-2008-4250 (MS08-067), a critical Windows Server service vulnerability that enabled unauthenticated remote code execution through crafted RPC requests over SMB. Conficker also inhibited host recovery by resetting Windows System Restore points and deleting backup files.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm that propagated through the MS08-067 SMB vulnerability.
Worm activity that removes restore points/backups to hinder remediation.
Referenced as historical background for collaborative cyber defense, not as an active threat actor group in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.