Orbit Downloader is a Microsoft Windows download manager developed by Innoshock and first released on 8 November 2006. Although originally distributed as free ad-supported software, it was later classified as malware after ESET reported on 21 August 2013 that versions starting with 4.1.1.15 contained a hidden botnet-like module capable of performing DDoS attacks without the user’s knowledge or permission. The project had effectively been abandoned by its developers by 2009, and the final listed release was version 4.1.1.19 on 17 January 2014. Orbit Downloader supported downloads over HTTP, HTTPS, FTP, Metalink, RTSP, MMS, and RTMP, integrated with Internet Explorer, Maxthon, Mozilla Firefox, and Opera, and was known for downloading embedded Flash video from online platforms. Prior to the DDoS disclosure, the software was also described as ad-supported and bundled with browser homepage changes, optional non-essential software offers, and built-in advertisements in the program window and download completion dialogs. Following ESET’s disclosure, major download sites including BetaNews, Download.com, DownloadCrew, MajorGeeks, Softpedia, and Softonic disabled or blocked downloads of the software; Softonic described it as containing a trojan. High-confidence indicators from the content include the affected version range beginning at 4.1.1.15 and the hidden DDoS functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
2006 Agent.AWF Archiveus Clickbot Orbit Downloader Rustock Stration Zlob
Originally a Windows download manager, Orbit Downloader was later found to include a hidden botnet-like component that could perform DDoS attacks without user knowledge, leading antivirus vendors to classify it as malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.