Mariposa was a large Spain-linked criminal botnet operation active around 2009–2010 and associated with operators using the aliases Netkairo, Ostiator, and Johny Loleante. It functioned as a malware distribution and botnet-for-rent platform, enabling downstream criminal activity including delivery of additional malware such as ZeuS, theft of sensitive information, bank fraud, and money laundering. Spanish authorities and private-sector investigators linked the operation to suspects arrested in Spain after an international investigation involving the Guardia Civil, the FBI, Panda Security, and Defence Intelligence. The botnet was disrupted in late 2009, but residual infections and numerous variants persisted afterward. Mariposa infected Windows systems at very large scale across many countries and sectors, including home users, companies, government agencies, universities, and business networks associated with control system owners. Reported infections included business environments in the United States, including a utility company’s corporate network, although there was no evidence in that case that control systems themselves were affected. Investigators assessed that infections were not necessarily aimed at a specific critical-infrastructure sector and could spread opportunistically. Operationally, Mariposa supported initial access and post-compromise control through malware propagation, persistence, and command-and-control over UDP. Documented behavior included spreading via removable media and poisoned pirated software distributed on peer-to-peer networks, dropping additional components, modifying Windows settings for persistence, and using code injection techniques. The botnet’s operators allegedly rented access to other criminals, who used the infected population for malware delivery and data theft. Investigators also noted that abandoned or disrupted Mariposa infections could remain on systems and potentially be reactivated or commandeered by other actors if command-and-control capability were re-established. Mariposa is best understood as a financially motivated cybercriminal botnet rather than a state-sponsored threat actor. Its known aliases are limited, with Mariposa being the primary name used for the operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A criminal botnet operation whose malware infected business networks, including a U.S. utility environment, using USB-based spread and UDP command-and-control communications. The original C2 infrastructure was disrupted, but residual malware and the risk of takeover by new operators remained.
A criminal botnet operation run by individuals including Netkairo and Ostiator that rented access to a large global network of compromised computers, distributed malware, stole sensitive data, and facilitated bank fraud and money laundering.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.