Dorkbot is a Windows malware family best known as a worm and IRC-controlled bot that spread widely through instant messaging, social media, removable media, and malicious links on websites. It propagated aggressively through Facebook and other messaging channels using social-engineering lures, and also spread via USB drives, making it effective in both consumer and enterprise environments. Related activity included deceptive links masquerading as images or other benign content to induce execution.
Once installed, Dorkbot provided backdoor access to infected systems and connected to command-and-control infrastructure over IRC. Operators could use infected hosts to download and execute additional payloads, update the malware, distribute spam, and participate in distributed denial-of-service activity. The malware was also used for credential theft, including harvesting login data through form grabbing and theft of cached or stored credentials from browsers and network client applications. Reported theft targets included online and banking-related credentials.
Dorkbot also exhibited defensive interference and traffic manipulation behavior, including blocking or redirecting users away from security-related websites. Variants and associated samples have been observed using process injection techniques, including Early Bird APC injection, as part of post-compromise execution and evasion tradecraft. The family was sufficiently prevalent that Microsoft reported large-scale monthly detections in 2015, and a joint disruption operation by Microsoft and law enforcement targeted the botnet infrastructure in December 2015.
Dorkbot is commonly referred to as Backdoor.IRCBot.Dorkbot in vendor naming, reflecting its dual role as a worm and IRC bot with backdoor functionality. Its historical impact stems from its combination of social propagation, credential theft, modular payload delivery, and botnet monetization through spam and DDoS operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Dorkbot is a family of malware worms that spreads through instant messaging, USB drives, websites or social media channels like Facebook.
Dorkbot is a family of malware worms that spreads through instant messaging, USB drives, websites or social media channels like Facebook. Code Shikara is a computer worm, related to the Dorkbot family, that attacks through social engineering.
Sophos reported in November 2011 that this threat mainly spreads itself through malicious links through the social network Facebook... The biggest risk is that someone's Facebook contacts may have had their account already compromised... and that the account user has been allured by clicking on a link seemingly posted by one of their friends.
The Spamhaus Botnet C&C (BGPCC) is designed to protect networks and their users from botnet traffic. It can be used to block traffic from/to servers on the internet that are operated by cybercriminals and used to control infected computers (bots) or exfiltrate data.
Download and run a file from a specified URL... Besides stealing usernames and passwords, the bot herder may also order additional malware downloads... After the code is launched, it attempts to download further malicious software hosted on a specific compromised Israeli domain.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware / Outils # Mycelium Framework (botnet) Mirai (botnet) DorkBot (botnet) RageBot (botnet) Phorpiex (botnet) IRCBot.HI (botnet)
A malware worm family with backdoor functionality that spreads via instant messaging, USB drives, websites, and social media. It can download and execute files from attacker-controlled URLs, steal credentials via form grabbing and cached logins, redirect or block domains, send spam, participate in DDoS attacks, and harvest credentials including banking-related logins.
Referenced as another malware family observed using the 'Early Bird' APC-based code injection technique.
A worm associated with 156 command-and-control servers identified by Spamhaus.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.