Brontok is a Windows worm first discovered in 2005 and described as having originated in Indonesia. It spreads primarily via email attachments, commonly using the filename kangen.exe and an Indonesian-language lure with some English text. It also uses its own mailing engine to send itself to email addresses found on the infected system and spoofs the infected user’s email address as the sender.
On execution, Brontok copies itself into the user’s application data directory and establishes persistence through the Windows Run registry key at HKLM\Software\Microsoft\Windows\CurrentVersion\Run. Reported behaviors include disabling Registry Editor (regedit.exe), modifying Windows Explorer settings, removing the Folder Options menu entry to hinder access to hidden files, turning off the Windows firewall, preventing file downloads, and causing the system to restart when the user opens Command Prompt. Some variants reboot the computer when window titles contain certain strings such as "application data," and the worm may blank typed addresses in Windows Explorer before completion.
Brontok also propagates by creating deceptive executable files inside folders and on mapped network drives using names that mimic the folder name, such as documents.exe inside a documents folder. It may open the default browser and load an HTML page stored in the My Pictures or Pictures folder. The content also states that Brontok carried out ping flood attacks against Israel.gov.il, playboy.com, and other .com sites, and may have been used in a hacktivist context.
Variants mentioned include Brontok.A, .D, .F, .G, .H, .I, .K, .Q, .U, and .BH. Additional detection names cited include W32/Rontokbro.gen@MM, W32.Rontokbro@mm, W32/Korbo-B, Worm/Brontok.a, Win32.Brontok.A@mm, W32/Brontok.C.worm, Win32/Brontok.E, Win32/Brontok.X@mm, and W32.Rontokbro.D@mm. The most affected countries identified in the content were Russia, Vietnam, and Brazil, with additional impact noted in Spain, Mexico, Iran, Azerbaijan, India, and the Philippines. The content states that Brontok can generally be removed by mainstream antivirus products and standalone removal tools.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
2005 Brontok Emcodec Extended Copy Protection PGPCoder PoisonIvy Samy SpySheriff
A Windows worm that spreads via email attachments, copies itself into the user's application data directory, establishes persistence via the Run registry key, disables regedit and Folder Options, turns off the Windows firewall, spreads using its own mailing engine, creates deceptive .exe files in folders and mapped network drives, and in some variants conducts ping flood attacks against websites.
Win32/Brontok [[URL_b3187638_464]] 2006 年 11 月 (1.22)
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.