Attackers ran a large-scale malware operation that compromised legitimate websites and replaced benign links with malicious ones, sending visitors to exploit infrastructure powered by Neosploit. The servers fingerprinted each victim and delivered tailored exploits against vulnerable components including Acrobat Reader, RealPlayer, PDF, SWF, and QuickTime, ultimately installing the Sinowal bootkit. The malware modified the master boot record (MBR), forced a reboot, and hid itself before the operating system loaded, giving it stealth and persistence while connecting to a fast-changing command-and-control network whose domains rotated multiple times per day.
Once systems were enrolled, the operation deployed an in-memory spyware DLL linked to Trojan-Spy.Win32.Sinowal that stole passwords, intercepted online banking sessions, redirected victims to phishing pages, and harvested credentials from numerous applications and financial sites. Reporting indicates the campaign reflected a modular, resilient criminal ecosystem rather than a single actor, combining exploit delivery, bootkit persistence, and banking fraud at significant scale; one estimate cited more than 200,000 U.S. visits to exploit servers in 24 hours and a botnet nearing 100,000 U.S. infected machines.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
The analysis reported that exploit servers received more than 200,000 U.S. visits in a 24-hour period and that the botnet size was approaching 100,000 U.S. bots. These figures indicated the campaign had reached significant scale.
Kaspersky's later analysis linked the bootkit to Trojan-Spy.Win32.Sinowal based on shared obfuscation methods and identical spyware behavior. The report also assessed that multiple cooperating criminal groups were likely involved rather than a single actor.
After botnet enrollment in 2008, the malware loaded an in-memory DLL spyware module that stole passwords, intercepted banking traffic, redirected users to phishing pages, and harvested credentials from many applications and online banking sites. This represented the campaign's monetization phase.
Once installed in 2008, the bootkit connected to a command-and-control infrastructure whose domains changed multiple times per day. The resilient botnet architecture helped the operators maintain control and evade disruption.
After successful exploitation in 2008, victims were infected with a bootkit identified as Sinowal that altered the master boot record, forced a reboot, and hid itself before the operating system loaded. This gave the malware stealth and persistence at a very early stage of system startup.
During the 2008 campaign, the attackers used the Neosploit exploit pack to profile visiting systems and deliver customized exploits targeting vulnerable software such as Acrobat Reader, RealPlayer, PDF, SWF, and QuickTime components. This personalized exploitation increased infection success rates.
In 2008, attackers replaced legitimate links on compromised websites with malicious ones that redirected visitors into an exploit chain. This marked the initial delivery stage of the campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.