Researchers and industry defenders reported that the Glupteba malware operation built unusual resilience by storing backup command-and-control information in Bitcoin OP_RETURN transaction data, allowing infected systems to recover infrastructure even after domains were seized. The botnet, active for years and at times exceeding 1 million infected devices, spread through pay-per-install networks, fake or cracked software installers, and laterally via EternalBlue-style propagation, while also targeting routers from vendors including MikroTik and Netgear. Analyses from ESET, Sophos, Nozomi Networks, and others described a modular platform with backdoor access, credential theft, proxying, rootkit features, persistence through Windows Registry changes, and evolving encryption and obfuscation methods.
Google said it disrupted parts of the operation through technical action and a civil lawsuit against alleged operators Dmitry Starovikov and Alexander Filippov, arguing that Glupteba supported a broader criminal ecosystem involving stolen accounts, payment-card abuse, cryptojacking, ad fraud, and residential proxy services such as AWM Proxy, Dont.farm, and Trafspin. Subsequent reporting and research tied the botnet to proxy infrastructure, compromised MikroTik devices, and overlapping monetization services, while showing that the operators adapted after disruption by rebuilding command infrastructure, increasing wallet usage, and expanding Tor-based services. The case highlighted how blockchain-backed recovery mechanisms and diversified criminal revenue streams made Glupteba unusually difficult to eradicate.

Pull IOCs and campaign context straight into your stack.
27 events from the most recent confirmed update back to the earliest known activity.
On December 15, 2022, Nozomi Networks published research reconstructing four Glupteba campaigns from 2019 through 2022 by scanning Bitcoin OP_RETURN data, reverse engineering samples, and correlating DNS and certificate data. The report concluded that Google's 2021 disruption appeared to shorten one campaign, but Glupteba rebuilt and scaled up in 2022.
Nozomi said the latest identified Glupteba Bitcoin transaction in its investigation was dated 2022-11-08. The embedded payload in that transaction was 000c0b0006171c11064d150a0b16.
On June 28, 2022, Krebs on Security published research linking AWM Proxy's founder to one of the men sued by Google over Glupteba. The article also said AWM Proxy remained active after disruption under new branding and was advertising about 175,000 infected systems over the prior 24 hours.
Nozomi reported that a fourth and ongoing Glupteba campaign began in June 2022 and significantly increased the number of Bitcoin wallet addresses used. The campaign also showed a tenfold increase in Tor hidden services used as C2 compared with the 2021 campaign.
Krebs reported that the United States, Germany, the Netherlands, and the United Kingdom dismantled the RSOCKS botnet earlier that month. The article discussed overlap between RSOCKS and AWM Proxy infrastructure and inventory.
Krebs reported that AWM Proxy went offline on the same day Google announced its action against Glupteba. Spur.us also found that RSOCKS proxy counts dropped to zero on December 7, 2021 after Google's action.
On December 7, 2021, Google announced that it was suing two Russian men allegedly responsible for Glupteba and had taken technical measures to dismantle the botnet. Google said Glupteba had infected more than one million devices worldwide and highlighted its blockchain-based resiliency.
Google filed a complaint for damages and injunctive relief in the Southern District of New York on December 2, 2021 against Dmitry Starovikov, Alexander Filippov, and unnamed co-conspirators. The filing alleged the Glupteba enterprise infected more than one million devices and used them for credential theft, fraud, proxy services, disruptive ads, and cryptojacking.
Google's complaint states that AWMProxy.net was rebranded as Vd.net on November 23, 2021. Google alleged AWMProxy sold residential proxy access using IP addresses of Glupteba-infected devices.
Nozomi reported that a third Glupteba campaign began in November 2021 and used four Bitcoin wallet addresses. It was the first campaign observed using Tor hidden services as command-and-control servers.
QRator Labs described the Mēris botnet on September 7, 2021 as a large botnet abusing MikroTik devices to launch major DDoS attacks. Avast later linked related infrastructure and behavior to Glupteba-associated activity.
Avast reported that the day after QRator Labs published its Mēris report, the C2 server stopped serving scripts, and it disappeared completely the following day. This indicated a rapid operational change after public exposure.
Avast reported that the first recorded VirusTotal submission of an ARM32 SOCKS proxy sample linked to Glupteba infrastructure occurred in November 2020. The sample contacted tik.anyget.ru to download a JSON list of IP addresses.
Nozomi reported that a second Glupteba campaign began in April 2020 and used two Bitcoin addresses, including 1CgPCp3E9399ZFodMnTSSvaf5TpGiym2N1. The domain deepsound[.]live may have been used for testing in this campaign.
Google said that in summer 2020 it observed Glupteba being distributed through third-party software download sites, online movie streaming sites, and video downloader sites advertised as free downloads. The complaint says the malware masqueraded as freeware, videos, or movies.
On September 4, 2019, Trend Micro reported a malvertising campaign distributing a new Glupteba variant that stole browser data and exploited MikroTik routers via CVE-2018-14847 to turn them into SOCKS proxies. The report also documented Glupteba recovering updated command-and-control domains from Bitcoin OP_RETURN transaction data, including venoxcontrol[.]com.
The first Glupteba campaign identified by Nozomi began in June 2019 and used the Bitcoin wallet address 15y7dskU5TqNHXRtu5wzBpXdY5mT4RZNC6. This marks Glupteba's use of the Bitcoin blockchain for command-and-control distribution since at least 2019.
Google's complaint states that Dont.farm claimed to have operated since 2019. The site allegedly sold access to stolen Google and other online accounts through preloaded virtual machines.
On March 22, 2018, ESET published research concluding that Glupteba was no longer affiliated with Operation Windigo. It said Glupteba had evolved into its own botnet and was being distributed through a pay-per-install ecosystem.
CVE-2018-14847, a MikroTik authentication bypass and file access flaw affecting WinBox on TCP port 8291, was publicized and patched in 2018. Later investigations said many routers remained unpatched and exposed.
ESET captured four days of traffic from an infected Glupteba node in November 2017. The observations showed Glupteba being used beyond spam delivery, including as a proxy service for automated abuse.
ESET reported that Glupteba had been seen in 180 different countries since the beginning of 2017. Ukraine, Russia, and Turkey accounted for a quarter of detections in its telemetry.
On 2014-03-18, ESET published its Operation Windigo report linking Win32/Glupteba.M with Linux/Ebury, Linux/Cdorked, and Perl/Calfbot as components run by the same operator group. ESET said the campaign had affected more than 25,000 servers over two years, with over 10,000 still infected, and released a white paper and IOCs to support remediation.
Kaspersky Lab reported in 2011 that virtually all hacked systems rented through AWM Proxy had been compromised by TDSS/TDL-4. This tied the proxy service to a major malware distribution ecosystem.
ESET observed in 2011 that the TDL-4 bootkit was acting as a downloader that installed Glupteba among other malware. Google's complaint also states Glupteba was first noticed by cybersecurity experts in 2011 and initially associated with spam campaigns.
AWM Proxy launched in March 2008 as an anonymity service that rented access to hacked PCs. It later became a major criminal proxy service.
Google attributed Glupteba with high confidence to individuals connected to the Russia-based developer company Voltronwork, citing development infrastructure such as git.voltronwork.com and gitlamp.com. The research also linked companies associated with Voltronwork to AWMProxy, Trafspin, and dont[.]farm, expanding the mapped criminal ecosystem around the botnet.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 169 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
14 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcenozominetworks.com
Open sourcekrebsonsecurity.com
Open sourcedecoded.avast.io
Open sourcewelivesecurity.com
Open sourceweb-assets.esetstatic.com
Open sourcestorage.googleapis.com
Open sourcevirusbulletin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.