Back Orifice 2000, commonly abbreviated BO2K, is a Windows remote administration tool widely referenced in the provided content as malware or a trojanized remote-control program when used for unauthorized access. It is described as similar in function to Back Orifice and debuted on July 10, 1999 at DEF CON 7. The content states it was released by Cult of the Dead Cow, with original code written by Dildog, and that it supported Windows 95/98 as well as Windows NT/2000/XP. One cited source notes it was released under the GPL. The content also associates BO2K with email-based spreading attempts: in October 2000, Rik van Riel reported a spam message with subject "Free eurocalculator!!!" carrying an attachment named "eurocalculator.exe" whose strings indicated "Back Orifice 2000 (BO2K)" components. Strings reportedly referenced reboot and lockup actions, RO/RW passwords, HTML content, and SMTP-related functionality, leading to an assessment that the sample was likely an attempt to spread BO2K through email, possibly with self-propagation, although that was not confirmed because the file was not executed. Additional historical context in the content notes that copies of BO2K distributed to DEF CON 7 attendees were themselves found infected with the CIH virus. High-confidence indicators and artifacts directly mentioned include the alias BO2K, the string "Version: Back Orifice 2000 (BO2K) v%1.1u.%1.1u," the lure subject "Free eurocalculator!!!," and the attachment name "eurocalculator.exe."
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
1999: Cult of the Dead Cow releases Back Orifice 2000 at DEF CON.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
CIH spread globally through pirated software channels in the summer of 1998, but several infections came from legit commercial sources like IBM’s Aptiva PCs, a batch of which shipped with CIH pre-installed in March 1999... Yamaha also distributed an infected firmware update for its CD-R400 drives, and copies of the tool Back Orifice 2000 handed out at DEF CON 7 in July of the same year also carried the virus.
Back Orifice officially provides XOR encoding and 3DES encryption for protecting the communication.
The “Server command client” allows the controller sends C2 commands to the payload. The mechanism works as follows: The controller sends C2 commands to the payload, the payload executes the corresponding funcitonallity and then return it.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Successor to Back Orifice referenced for its server editor concept that influenced Sub7 customization and delivery.
Remote administration/backdoor tool released publicly; commonly treated as a RAT/backdoor.
Remote administration tool referenced as a distribution medium that was found infected with CIH (the content does not describe BO2K functionality beyond being a remote administration tool).
Successor to Back Orifice providing similar remote control functionality, with broader Windows version support; debuted at DEF CON 7 (1999).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.