Kelihos is a Windows peer-to-peer botnet and spam malware family active from at least 2010 until its disruption in 2017. It used a decentralized peer-to-peer command-and-control design to make infrastructure takedowns more difficult and was associated with Russian cybercriminal Peter Yuryevich Levashov, also known as Severa. Kelihos compromised large numbers of Windows systems and was used to distribute bulk spam, harvest account credentials, support pump-and-dump stock fraud, conduct denial-of-service attacks, and deliver ransomware, banking Trojans, and other payloads. Operators rented botnet capacity and malware-distribution services to other criminals. Historical variants spread through social-network worm activity, and the malware was repeatedly re-crypted to evade antivirus detection. Law-enforcement and private-sector operations sinkholed Kelihos networks on multiple occasions; operators responded by releasing protocol-incompatible variants and rebuilding portions of the botnet.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Pyotr Levashov, also known as Severa, operated rogue antivirus partnerkas ... in addition to spreading the infamous Waledac and Kelihos botnets.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The Department of Justice said that Levashov “controlled and operated multiple botnets, including the Storm, Waledac, and Kelihos botnets to harvest personal information and means of identification (including email addresses, usernames and logins, and passwords) from infected computers.”
Severa rented out segments of his Waledac botnet to anyone seeking a vehicle for sending spam. For $200, vetted users could hire his botnet to blast one million emails containing malware or ads for male enhancement drugs.
Levashov controlled and operated multiple botnets, including the Storm, Waledac and Kelihos botnets
We’ve taken down Waledac, Rustock and Kelihos. All of them basically spam bots. But that disruptive activity has dented the amount of spam that gets sent out.
which he used to facilitate malicious activities including harvesting login credentials, distributing bulk spam e-mails, and installing ransomware and other malicious software
Kelihos was still being spread using a Facebook worm with communication with the command and control (C&C) server through other members of the botnet
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a prior botnet disruption that used peer-list manipulation.
Mentioned only as a historical example of a botnet disruption using peer-list manipulation.
Mentioned only in source links as related background on botnet takeover activity.
A global spam botnet linked to Peter Levashov, used in spam operations and deployed via his SevAntivir fake antivirus affiliate program; it shared substantial code with Waledac.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.