Coreflood is a credential-stealing trojan and botnet malware family that operated at large scale in the early 2010s. It is commonly identified as Backdoor.Coreflood because it opens a backdoor on compromised Windows systems while also performing surveillance and data theft. Reported functionality includes keylogging and collection of user information from infected hosts, enabling theft of credentials and other sensitive data. Coreflood infections were observed across a broad victim set including government entities, airports, defense contractors, financial institutions, universities, healthcare organizations, and numerous private-sector businesses. Public reporting attributed the malware to a Russian criminal group and estimated that the botnet had infected more than 2.3 million computers worldwide. In 2011, a coordinated U.S. law-enforcement disruption significantly reduced the botnet’s size after court-authorized action against infected systems with victim consent.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The CERT/CC has received reports of this vulnerability being exploited to install backdoors and DDoS tools... References ... backdoor.coreflood
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-stealing malware referenced only as an example of password theft trends.
Trojan/botnet malware that opens a backdoor on compromised systems, performs keylogging, and collects user information; operated at large scale (millions of infected hosts) and was subject to an FBI-led disruption and court-authorized removal with user consent.
Named trojan referenced as discovered in 2010; no additional technical behavior described in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.