AFX Windows Rootkit 2003 is a Windows user-mode rootkit from 2003. It is described as hiding files, processes, and registry entries by hooking Windows API functions. According to the provided content, when installed it creates two DLL files, iexplore.dll and explorer.dll, in the system directory, injects iexplore.dll into explorer.exe, and injects explorer.dll into all running processes. Its payload uses API hooking to conceal malicious artifacts from users and the operating system. The content references Microsoft’s Trojan:Win32/Delf.M entry, but does not provide high-confidence attribution to a specific threat actor, infection vector, or targeted industry. Known artifacts directly mentioned in the content include the DLL filenames iexplore.dll and explorer.dll and the injection target explorer.exe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows user-mode rootkit that installs DLLs, injects them into explorer.exe and other running processes, and hooks Windows API functions to hide files, processes, and registry entries.
2003 AFX Windows Rootkit 2003 Blaster Graybird Gruel Mumu Sobig SQL Slammer Welchia
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.