Mariposa was a large criminal botnet and malware platform first observed in 2008 and disrupted in late 2009. It primarily targeted Microsoft Windows systems and was designed to compromise endpoints, enroll them into a remotely controlled botnet, and steal sensitive information including banking, email, and other online account credentials. Mariposa also functioned as a malware distribution service, allowing operators and customers to deploy additional payloads such as banking trojans, keyloggers, remote access trojans, and pay-per-install software onto infected hosts.
The malware was associated with the DDP Team and has been linked in court proceedings and law-enforcement reporting to Matjaž Škorjanc, also known as Iserdo, who was convicted in Slovenia for creating the malware used to power the botnet. Mariposa was marketed on the Darkode cybercrime forum beginning in 2008, with advertised capabilities including self-propagation, banking credential theft, and distributed denial-of-service attacks. Operators and affiliates monetized the botnet through credential theft, bank fraud, spam operations, pay-per-install schemes, and resale of access to compromised machines.
Observed propagation methods included peer-to-peer file-sharing networks, removable media such as USB drives, and malicious links sent through instant messaging. Incident reporting also documented spread inside enterprise environments after an infected laptop was reconnected to a corporate network. Technical analysis tied Mariposa variants to dropped components, Windows persistence via Winlogon modification, outbound UDP-based command-and-control traffic, and code-injection behavior. Even after the primary command-and-control infrastructure was disrupted, residual infections remained a risk because abandoned botnet infections could potentially be reactivated or repurposed.
Mariposa infected systems globally across more than 190 countries and affected home users, enterprises, universities, and government organizations. Investigations also identified infections in business networks of multiple control system owners, although no evidence indicated that affected industrial control systems themselves were compromised in the documented utility case. Mariposa is widely regarded as one of the most significant botnets of its era because of its scale, aggressive propagation, credential-theft focus, and use as a general-purpose criminal delivery platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
As previously reported, the Mariposa botnet was principally geared towards stealing online login credentials for banks, email services and the like from compromised Windows PCs.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
USUTIL1’s investigation found that the initial infection vector may have been a USB drive shared at an industry conference. An instructor shared a USB drive among participants at a training event attended by USUTIL1’s employee.
The four not only sold copies of the Mariposa bot, but they also actively infected victims and sold access to the infected hosts in "pay-per-install" schemes that let other cyber-criminals install additional malware on these systems, such as ransomware or banking trojans.
As previously reported, the Mariposa botnet was principally geared towards stealing online login credentials for banks, email services and the like from compromised Windows PCs.
Once infected by the Mariposa bot client, compromised machines would have various strains of malware installed (advanced keyloggers, banking trojans like Zeus, remote access trojans, etc) by the hackers to obtain greater control of infected systems.
Once installed its operators could command the compromised machines to carry out their instructions including sending back copies of data they stored.
As previously reported, the Mariposa botnet was principally geared towards stealing online login credentials for banks, email services and the like from compromised Windows PCs.
The initial outbound packet is 49 bytes (7 bytes encrypted payload) to hnox[dot]org or socksa[dot]com, using UDP port 21039, for the purpose of establishing the C2 channel. The C2 server responds from 21039 to the same local port, with a UDP packet of varying length and encrypted payload.
Spanish police say the break in the case came when one of the members of the Mariposa gang made an amateur mistake: Accessing the botnet’s control networks directly from his home Internet address instead of anonymizing his connection by relaying it through a mesh of third-party systems.
This proved difficult to do because the hackers only connected to the net via a virtual private network (VPN), which hid their locations.
47 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware 2008 Asprox Agent.BTZ Mariposa
A destructive and once-prolific botnet malware family used to infect hacked computers at massive scale; the content says it powered the Mariposa botnet, which was first spotted in 2008 and infected more than 1 million computers.
A self-propagating malware family used to build the Mariposa botnet. It could spread to other computers, steal banking credentials, and launch DDoS attacks; operators also sold access to infected hosts for pay-per-install schemes.
2008 ... Agent.BTZ Mariposa
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.