Gumblar is a Windows-focused malicious JavaScript trojan and botnet active from 2009 that became notable for combining website compromise, traffic redirection, credential theft, and automated reinfection of web content. It is also known as Troj/JSRedir-R. The malware redirected users from compromised websites and manipulated search traffic, including Google search results, to send victims to attacker-controlled pages that delivered additional malware, including infected PDF exploit content and later fake antivirus or rogue security software. Its operators used compromised legitimate websites as a distribution layer, making Gumblar both an end-user infection threat and a web ecosystem compromise campaign.
A defining feature of Gumblar was theft of FTP credentials from infected Windows systems. It searched for credentials stored by common FTP and web-authoring applications and also captured FTP authentication data from local network traffic by enabling promiscuous-mode sniffing. The stolen credentials were then used to log into websites with valid administrator or maintainer access and modify web content. Gumblar injected malicious code into web pages and scripts, including HTML, PHP, JavaScript, ASP, and ASPX content, and also altered server configuration-related files to sustain redirection and reinfection behavior. This allowed the malware to propagate through compromised websites without indiscriminately exploiting servers, instead abusing legitimate credentials to infect sites and expose their visitors to further malware delivery.
Gumblar is associated with botnet activity and with server-side polymorphism techniques that complicated detection by varying delivered malicious content over time. After early infrastructure was disrupted in 2009, related variants continued operating through alternate infrastructure and resurfaced in 2010 with renewed FTP credential theft and website infection activity. Gumblar is best characterized as a web-propagating credential-stealing malware operation centered on compromised websites, malicious script injection, and secondary malware delivery to Windows victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Using passwords obtained from site admins, the host site will access a website via FTP and infect that website.
Using passwords obtained from site admins, the host site will access a website via FTP and infect that website.
Visitors to an infected site will be redirected to an alternative site containing further malware... The site sends the visitor an infected PDF that is opened by the visitor's browser or Acrobat Reader. The PDF will then exploit a known vulnerability in Acrobat to gain access to the user's computer.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as incidental prior implant activity on devices behind routers.
Mentioned as a comparison point for similar propagation and script obfuscation techniques.
Referenced as earlier malware known to have used server-side polymorphism, for comparison with Cerber.
JavaScript-based malware/botnet that redirects search traffic, delivers further malware including rogue security software, steals FTP credentials from clients such as FileZilla and Dreamweaver, enables promiscuous mode to sniff network traffic for FTP details, and propagates by injecting malicious code into website files on compromised servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.