Conficker, also known as Downadup and Kido, is a highly prolific Windows worm first identified in 2008 that spread globally by exploiting the MS08-067 Windows Server service vulnerability and by propagating across local networks and removable media. It became one of the most significant malware outbreaks of its era, infecting millions of systems and assembling them into a large botnet.
Conficker is designed for self-propagation, persistence, and botnet enablement. It copies itself into the Windows system directory, registers itself as a service, modifies multiple Registry locations, and has been reported to use NTFS Alternate Data Streams to conceal components. It scans for additional machines to infect, communicates with command-and-control infrastructure over HTTP, and later variants incorporated peer-to-peer update and command distribution mechanisms. A defining feature of the family was its domain-generation algorithm, which produced large numbers of pseudo-random domains for resilient command-and-control discovery; later variants greatly expanded the number of candidate domains generated each day, complicating sinkholing and takedown efforts.
The worm is also associated with defense evasion and recovery inhibition. Reported behaviors include terminating Windows and security-related services, interfering with access to security resources, and deleting restore points and backup-related data. Conficker has also been observed downloading and launching additional payloads, making the botnet a platform for follow-on criminal activity such as spam distribution, rogue security software delivery, fraud, and potentially other malware deployment.
Conficker primarily targets Windows environments, including enterprise and critical infrastructure systems that remained unpatched or exposed through weak internal segmentation and removable-media pathways. It has repeatedly been cited as a canonical example of the long-tail risk posed by unpatched legacy vulnerabilities. The malware has been linked in reporting to large criminal botnet ecosystems, and some reporting has alleged possible overlap with actors involved in major spam affiliate operations, though attribution to specific operators remains less certain than the malware’s technical characteristics and widespread criminal use.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...MS08-067 (CVE-2008-4250), which was a propagation vector of the infamous Conficker worm. | So exploit variants or encrypted exploits can be generated for many RPC vulnerabilities – such as MS08-067 (CVE-2008-4250), which was a propagation vector of the infamous Conficker worm.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
The best way to defeat potential botnets like Conficker/Downadup is by the security and Domain Name System communities working together.
As you can see in the list below, it relies upon computers using poorly chosen passwords such as dictionary words, “password”, “qwerty” or sequences of letters or repeated numbers.
As you can see in the list below, it relies upon computers using poorly chosen passwords such as dictionary words, “password”, “qwerty” or sequences of letters or repeated numbers.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
As you can see in the list below, it relies upon computers using poorly chosen passwords such as dictionary words, “password”, “qwerty” or sequences of letters or repeated numbers.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
As you can see in the list below, it relies upon computers using poorly chosen passwords such as dictionary words, “password”, “qwerty” or sequences of letters or repeated numbers.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
One of the ways in which the Conficker worm (also known as Confick or Downadup) uses to spread is to try and batter its way into ADMIN$ shares using a long list of different passwords.
Where before all the infected computers would have to phone home to a single source for instructions, the authors could now use any infected computer to instruct all the others.
Botnet Conficker ... wykorzystuje do komunikacji ze swoim centrum kontroli (Command & Control) protokół HTTP, łącząc się z serwerem ... na porcie 80. w celu pobrania nowego pliku binarnego.
Each packet has an encryption key, some data and a checksum (encrypted), and some noise. By sending a packet to an infected host on any of its ports, the host will respond. | When Conficker.C or higher infects a system, it opens four ports for communication (two TCP and two UDP). It uses these to connect to other infected hosts to send/receive updates and other information.
... wykorzystuje do komunikacji ze swoim centrum kontroli (Command & Control) protokół HTTP ... w celu pobrania nowego pliku binarnego.
Serwery, z którymi łączy się bot, lokalizowane są z wykorzystaniem DNS, poprzez pseudolosową codzienną generację nowej listy kilkuset domen (najnowsza wersja Confickera generuje nawet 50 000 domen dziennie – najbardziej obecnie popularna wersja generuje tylko 450 domen).
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
95 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical worm outbreak used for comparison with the proposed Intelligent Worm model.
Conficker is referenced as a major historical worm threat from an earlier era of cybersecurity.
Conficker is referenced only as part of an Nmap host script check for signs of Conficker.C infection; the scan result indicates the host is clean or ports are blocked.
A worm/botnet referenced as a historical example of large-scale DGA-based command-and-control resilience.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.