DorkBot is a Windows malware family best known as a worm-operated botnet with backdoor and credential-theft functionality. It spread widely in the early-to-mid 2010s through instant messaging, removable drives, malicious websites, and social-media lures, especially Facebook messages and posts sent from compromised accounts. Campaigns also used deceptive files masquerading as images or other benign content to induce execution.
Once installed, DorkBot provided remote operators with control over infected systems through IRC-based command-and-control. Infected hosts could be instructed to download and execute additional malware, update themselves, send spam, participate in distributed denial-of-service activity, and support broader botnet operations. The malware was also used to steal credentials and other sensitive information, including through form grabbing and theft of cached or stored login data from browsers and network client applications. Reported theft targets included online-service and banking credentials.
DorkBot also exhibited defensive interference and user-manipulation behavior by blocking or redirecting access to selected websites, including security-related destinations, which hindered remediation and analysis. Variants have been associated with process-injection tradecraft, including use of the Early Bird APC injection technique to execute code in newly created suspended processes before normal thread startup reaches common monitoring points.
The family was tracked extensively by multiple security vendors and law-enforcement partners due to its scale and longevity. Microsoft reported substantial global infection volumes during 2015, and a joint disruption operation involving Microsoft and the FBI dismantled major DorkBot botnet infrastructure in December 2015. DorkBot remains notable as a socially propagated worm-bot that combined self-spread, backdoor access, credential theft, spam distribution, and DDoS enablement in a single criminal platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Dorkbot is a family of malware worms that spreads through instant messaging, USB drives, websites or social media channels like Facebook.
Dorkbot is a family of malware worms that spreads through instant messaging, USB drives, websites or social media channels like Facebook. Code Shikara is a computer worm, related to the Dorkbot family, that attacks through social engineering.
Sophos reported in November 2011 that this threat mainly spreads itself through malicious links through the social network Facebook... The biggest risk is that someone's Facebook contacts may have had their account already compromised... and that the account user has been allured by clicking on a link seemingly posted by one of their friends.
The Spamhaus Botnet C&C (BGPCC) is designed to protect networks and their users from botnet traffic. It can be used to block traffic from/to servers on the internet that are operated by cybercriminals and used to control infected computers (bots) or exfiltrate data.
Download and run a file from a specified URL... Besides stealing usernames and passwords, the bot herder may also order additional malware downloads... After the code is launched, it attempts to download further malicious software hosted on a specific compromised Israeli domain.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware / Outils # Mycelium Framework (botnet) Mirai (botnet) DorkBot (botnet) RageBot (botnet) Phorpiex (botnet) IRCBot.HI (botnet)
A malware worm family with backdoor functionality that spreads via instant messaging, USB drives, websites, and social media. It can download and execute files from attacker-controlled URLs, steal credentials via form grabbing and cached logins, redirect or block domains, send spam, participate in DDoS attacks, and harvest credentials including banking-related logins.
Referenced as another malware family observed using the 'Early Bird' APC-based code injection technique.
A worm associated with 156 command-and-control servers identified by Spamhaus.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.