Glupteba is a Windows malware family used in the Windigo cybercrime operation as a proxy-oriented payload delivered through drive-by exploitation. In the documented Windigo distribution chain, compromised web infrastructure redirected visitors to exploit kits, which then installed Glupteba on victims outside selected English-speaking countries. The malware was commonly delivered as an installer package and established itself on Windows systems as a service.
Within Windigo, Glupteba functioned primarily as a remotely controlled proxy bot. After installation it contacted command-and-control infrastructure over HTTP, identified the infected host, retrieved updated connection information, and then communicated over a secondary protocol to receive tasking. Supported commands included creating proxy connections, closing sockets, updating configuration data, modifying system settings, and downloading and executing additional payloads. Investigated infections were used as spam proxies, with traffic patterns indicating the bots were tested for outbound web and SMTP connectivity before being used operationally.
The family is associated with the broader Windigo ecosystem, which linked Linux server compromises, web-traffic redirection, credential theft, and large-scale spam monetization. In that ecosystem, Glupteba was one of the Windows endpoints monetized through exploit-kit delivery from compromised servers. High-confidence reporting ties its command infrastructure to servers also involved in other Windigo components, particularly Linux/Ebury. The malware targets Windows systems and is notable in this context for proxying and payload retrieval rather than credential theft or click fraud.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
web visitors accessing pages hosted on websites infected with Linux/Cdorked can be redirected to exploit kits. These exploit kits, if successful, install two different malware families, depending on the visitor’s geographic location. | Web servers infected with Linux/Cdorked redirect users to exploit kit servers, which in turn attempt to infect users with malware.
The normal operation of the bot is to query the server using an HTTP GET request over HTTPS carrying a payload of encrypted and unencrypted data.
This server is the entry-point of a chain of reverse proxy servers terminating on an exploit serving machine. | In the interaction shown in the previous screenshot, the bot is instructed to establish a proxy connection with a remote host. In all instances we investigated, the bots are used as proxies to send spam.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows malware component linked to Operation Windigo and operated by the same group; used as part of the multi-component campaign affecting servers and desktop PCs.
A Windows malware family distributed via exploit kits in the Windigo ecosystem. It acts as a generic proxy and is used to relay spam after contacting its C2 and receiving commands.
Win32/Glupteba.M is installed via exploit kits, contacts hardcoded C2 infrastructure over HTTP, receives commands, and is used primarily as a proxy for sending spam after connectivity tests confirm outbound TCP/25 access.
A Windows malware family distributed via exploit kits in the Windigo ecosystem. It acts as a generic proxy and is used to relay spam after contacting its C2 and receiving commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.