Slenfbot is a Microsoft Windows malware family first observed in 2007 that functions as a worm, backdoor, botnet client, and downloader. It primarily spreads through social-engineering links and ZIP archives sent over instant messaging platforms including MSN/Windows Live Messenger, AOL Instant Messenger, Yahoo Messenger, Google Chat, Facebook Chat, ICQ, and Skype. It also propagates via removable drives and accessible network shares, and some variants reportedly spread by exploiting Microsoft vulnerabilities MS06-040 and MS10-061. After execution, Slenfbot copies itself into the Windows system directory using variant-dependent filenames, sets files as read-only, hidden, and system, and establishes persistence through registry modifications such as HKLM\Software\Microsoft\Windows\CurrentVersion\Run; some variants also install themselves as a debugger for ctfmon.exe. Reported defense-evasion and anti-remediation behavior includes deleting the original sample, authorizing itself through Windows Firewall, injecting into explorer.exe to monitor and restore the malware if removed, replacing the hosts file to block antivirus and security-related domains, and disabling or interfering with System Restore, Task Manager, Registry Editor, hidden-file viewing, antivirus, firewall protections, and DEP; some variants also terminate security processes and stop, disable, or delete services. Slenfbot contains IRC-based command-and-control functionality, connecting to IRC servers over variant-specific TCP ports and joining channels where operators can issue commands to delete the malware, join other channels, download and execute files, or continue propagating. It spreads through instant messaging by sending lure messages and ZIP archives to victims’ contacts, and through removable media by creating RECYCLER directory structures, copying itself under names such as folderopen.exe, and creating autorun.inf files; some variants use names such as ~secure on removable media. Slenfbot is also used as a first-stage payload to download additional malware, including spam bots, spyware, information stealers, and other malicious tools. One cited domain associated with Slenfbot activity is potenzmittelapotheke24.de, described in the content as a pill-spam domain heavily spammed by the Slenfbot botnet. The content also notes that Slenfbot’s codebase appears closely controlled, suggesting either a single operator group or substantial code sharing among related actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The worm then makes changes to the registry to maintain persistence so that the malware executes a duplicate copy on each subsequent startup of the system (e.g. copying the malicious executable to the HKLM\Software\Microsoft\Windows\CurrentVersion\Run subkey).
Certain Slenfbot variants may inject a thread into explorer.exe, which periodically checks for the presence of the malware in the System folder.
Slenfbot may also create an autorun.inf file in the root directory of the drive so that the worm may execute if the drive is connected to another system.
The worm then makes changes to the registry to maintain persistence so that the malware executes a duplicate copy on each subsequent startup of the system (e.g. copying the malicious executable to the HKLM\Software\Microsoft\Windows\CurrentVersion\Run subkey).
If Slenfbot is launched from a removable drive, some variants may open Windows Explorer and display the contents of the affected drive.
Certain Slenfbot variants may inject a thread into explorer.exe, which periodically checks for the presence of the malware in the System folder.
Slenfbot runs commands to delete files named *.zip and *.com in the current directory as well as the user's "Received Files" directory.
Slenfbot attempts to connect to an Internet Relay Chat (IRC) server via a particular TCP port ... joins a channel and then waits for commands.
Slenfbot may download and install additional malware to relay spam, steal information, install spyware toolbars as well as propagate other malicious campaigns. | If the file is not found, the malware downloads a new copy from a specified server and launches the new copy.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Slenfbot is described as a botnet used to heavily spam pill/pharmacy domains.
A Windows worm first seen in 2007 that spreads through instant messaging, removable drives, and network shares. It provides backdoor access, connects to IRC for command-and-control, persists via registry changes, disables security controls, and downloads additional malware such as spyware, information stealers, and spam bots.
Named botnet mentioned as a notable example.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.