CoreBot is a Windows banking Trojan and botnet malware family active in the mid-2010s and associated with financially motivated cybercrime. It has been identified among globally active PC banking Trojans and has been observed using resilient criminal infrastructure including Avalanche fast-flux services and Namecoin-based command-and-control support. CoreBot is commonly discussed alongside other banking malware families targeting financial institutions and online banking users.
Available reporting in this context supports CoreBot’s use of a domain generation algorithm for command-and-control resilience. It has also been linked to webinject activity through observed overlap in webinject naming with other banking-Trojan operations, indicating functionality aligned with browser-based financial fraud workflows. CoreBot has appeared in malware delivery ecosystems used by spam- and phishing-oriented operators, including campaigns attributed to TA547, which has distributed multiple banking malware families.
CoreBot primarily targets Microsoft Windows environments. Its operational context, infrastructure overlap, and classification within banking-Trojan reporting indicate a focus on credential and financial-data theft from banking victims, although the specific internal feature set is not fully established here beyond command-and-control resilience and webinject-related overlap.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Delivered malware included ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Avalanche used fast-flux DNS, a technique to hide the criminal servers, behind a constantly changing network of compromised systems acting as proxies.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PC banking trojan listed among malware actively used to attack companies.
Mentioned only as another malware family with a similar DGA bug.
Mentioned only as a technical comparison for shared RC4/LZMAT usage.
Delivered malware included ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.