Bobax, also known as Kraken, is a long-running Windows spam botnet malware family active since at least 2004. It is best known for large-scale unsolicited email distribution and operation as a rentable cybercrime platform, and at various times it ranked among the most prevalent global spam botnets. Bobax has been associated with substantial bot populations and sustained spam output over multiple years, including periods in which it was one of the leading sources of global spam.
Bobax is directly associated with botnet functionality and spam operations rather than targeted intrusion activity. It has been observed alongside other major mass-malware families in comparative malware research, where samples showed strong intra-family similarity but no evidence of broad code sharing with unrelated mass-malware or targeted-malware families. Samples attributed to Bobax were noted to implement process-injection behavior using common remote-process memory allocation and thread-creation APIs, indicating post-compromise execution within other processes as part of its operation.
Operational reporting tied Bobax to centralized command-and-control infrastructure and showed that disruption of its hosting and control servers materially affected the botnet’s activity. By late 2008, shutdown of the infrastructure supporting its control servers was followed by an apparent cessation of observed Bobax spam, illustrating its dependence on backend services despite its scale and longevity.
Bobax primarily targeted Windows systems as infected bots participating in spam campaigns. Its role in the criminal ecosystem was as a spambot botnet used for mass email delivery, and it has been discussed in the same operational context as other major spam botnets such as Rustock, Cutwail, Srizbi, Grum, and Mega-D.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The code incorporates a timestamp, which is determined by making an HTTP request to a randomly picked, legitimate website. The date is extracted from the http date header of the response and converted to unix timestamp format.
60 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prevalent spam botnet used as a comparison point for Lethic's ranking.
Spam botnet identified as one of the top spam-sending botnets, with an estimated size of 80,000 to 120,000 infected IPs.
A long-lived spam botnet active since 2004 that became one of the largest spam botnets, but later struggled due to disruption efforts and loss of its control servers.
Mass malware family covered in the study and specifically identified as using common code-injection APIs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.