Lethic, also referred to as Ddox in some reporting, is a Windows spambot botnet malware family first identified around 2008. It became notable for large-scale pharmaceutical and replica-product spam operations and at its peak was assessed as a major contributor to global spam volume, with hundreds of thousands of infected machines reported. Activity was observed heavily in Europe, India, and Southeast Asia, and the botnet’s infrastructure was disrupted in early 2010 before operators partially reconstituted it using new command-and-control infrastructure.
Lethic is characterized by modular, configurable spam-sending behavior rather than advanced stealth. Researchers described it as comparatively simple but effective, with no rootkit component observed in the cited reporting. Infected hosts attempted direct SMTP delivery and related spam traffic over multiple ports, consistent with bulk unsolicited email distribution and relay abuse. Sandbox observations also showed behavior consistent with looping through SMTP proxies or open relays to send spam.
The malware has been seen both as a standalone botnet family and as a final-stage payload delivered by other malware. One documented infection chain used Smoke Loader followed by Neutrino to retrieve multiple Lethic binaries onto compromised Windows systems. In those cases, Lethic established user-level autorun persistence and dropped multiple executables under deceptive locations, indicating use as a monetization payload after initial compromise by loader malware.
Lethic variants have also been associated with rapidly changing executable names and rotating network parameters, suggesting efforts to hinder static blocking and support botnet resilience. A 2010 resurgence drew attention because numerous samples carried forged-looking Realtek version-information metadata in their PE resources; this was not a valid digital signature, but it provided a useful clustering artifact across many related samples.
Operationally, Lethic’s primary role has been spam distribution rather than credential theft or destructive action. Reported spam themes included pharmaceutical offers and replica watches, and overlap with contemporaneous Bagle spam campaigns suggested either shared operators, shared customers, or common spam affiliate relationships. Lethic is best classified as a spam-focused botnet malware family targeting Windows endpoints for use in large-scale unsolicited email campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Following infection, connection attempts have been seen to: izuhjsn.com ... xkihjhx.com
an Anubis report shows a "Realtek" Lethic sample looping through a number of SMTP proxies/open-relays and sending spam
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A spambot/botnet payload delivered after Neutrino infection. It installs multiple binaries with persistence and generates SMTP and related spam-sending traffic over ports including 25, 5500, 6600, and 7700.
A spam-focused botnet active since around 2008, primarily used to send pharmaceutical and replica spam at large scale via hundreds of thousands of infected machines. It was temporarily dismantled in January 2010, then re-established using new command-and-control servers in the United States.
A spam-focused botnet malware family used to send pharma and replica spam, spread via changing ports and auto-generated executable names, and communicate with command-and-control infrastructure over registered domains.
A spam botnet observed sending pharmaceutical and replica watch spam. The content describes it as a sizeable botnet with minimal complexity compared to other spambots and notes its command-and-control servers were largely hosted at FDCservers.net.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.