Kelihos is a Windows botnet malware family and spam bot active since at least 2010, widely associated with Russian operator Peter Yuryevich Levashov, also known as Severa. It is closely related in lineage and code-sharing to Waledac and was rebuilt in multiple versions after repeated disruption attempts. Kelihos infected large numbers of Microsoft Windows systems and used a resilient peer-to-peer botnet architecture in at least some variants, enabling operators to maintain command-and-control through other infected nodes and rapidly reconstitute the network after sinkholing actions.
Kelihos was primarily used as a criminal service platform for bulk spam operations, credential harvesting, malware delivery, and other botnet-enabled abuse. Documented uses include harvesting login credentials and other account data from infected systems, sending large volumes of spam, supporting pump-and-dump stock spam campaigns, distributing ransomware and other malware, and conducting denial-of-service attacks. The botnet was also rented or otherwise made available to criminal affiliates, making it part of a broader malware-as-a-service ecosystem.
Distribution methods observed for Kelihos include social-network worm propagation, particularly via Facebook, and installation by third-party droppers consistent with pay-per-install arrangements. Operators also relied on crypter services to repeatedly re-pack the malware and reduce antivirus detection, including custom high-volume crypting support linked to Oleg Koshkin. Multiple takedowns targeted Kelihos in 2011, 2012, 2013, and 2017, but new variants appeared quickly after sinkholing efforts, underscoring the operators’ ability to modify the malware and redeploy the botnet.
Kelihos is best characterized as a spam-centric botnet with credential theft and malware delivery functions rather than a single-purpose payload. At various points it controlled tens of thousands to more than one hundred thousand compromised Windows computers worldwide, making it one of the more significant criminal botnets of its era.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Pyotr Levashov, also known as Severa, operated rogue antivirus partnerkas ... in addition to spreading the infamous Waledac and Kelihos botnets.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The Department of Justice said that Levashov “controlled and operated multiple botnets, including the Storm, Waledac, and Kelihos botnets to harvest personal information and means of identification (including email addresses, usernames and logins, and passwords) from infected computers.”
Severa rented out segments of his Waledac botnet to anyone seeking a vehicle for sending spam. For $200, vetted users could hire his botnet to blast one million emails containing malware or ads for male enhancement drugs.
Levashov controlled and operated multiple botnets, including the Storm, Waledac and Kelihos botnets
We’ve taken down Waledac, Rustock and Kelihos. All of them basically spam bots. But that disruptive activity has dented the amount of spam that gets sent out.
which he used to facilitate malicious activities including harvesting login credentials, distributing bulk spam e-mails, and installing ransomware and other malicious software
Kelihos was still being spread using a Facebook worm with communication with the command and control (C&C) server through other members of the botnet
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in source links as related background on botnet takeover activity.
A global spam botnet linked to Peter Levashov, used in spam operations and deployed via his SevAntivir fake antivirus affiliate program; it shared substantial code with Waledac.
Kelihos is a botnet malware used to send spam, harvest account credentials, conduct denial-of-service attacks, and distribute ransomware and other malicious software.
A large botnet active since at least 2010 that was used to send spam, harvest account credentials, conduct denial-of-service attacks, and distribute ransomware and other malicious software.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.