A new Conficker variant, also known as Kido or Downadup, reactivated infected hosts through peer-to-peer communications and resumed worm behavior by spreading between systems and downloading additional malware. Kaspersky reported that compromised machines pulled down a rogue antivirus detected as FraudTool.Win32.SpywareProtect2009.s and the Waledac email worm, detected as Email-Worm.Win32.Iksmas.atz, which added spam-sending and data-theft capabilities to already infected endpoints.
Technical analysis and sample listings show the malware propagated through multiple channels, including exploitation of MS08-067, SMB brute forcing, and removable media using autorun.inf and disguised DLL files. The worm established persistence, injected into processes such as Explorer.exe and Svchost.exe, blocked DNS access to security resources, altered TCP settings, disabled protections and services, deleted restore points, and used a domain generation algorithm to maintain resilience on legacy Windows systems, particularly older Windows XP environments.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
During the night of 8/9 April 2009, machines infected with Trojan-Downloader.Win32.Kido/Conficker.c contacted each other over peer-to-peer communications. Those instructions activated the Kido botnet and directed infected systems to download new malicious files.
Kaspersky said the Iksmas/Waledac malware was first detected in January 2009, and that many IT experts noted similarities between Kido and Iksmas at that time. It also said an email epidemic of similar scale to Kido was caused by Iksmas.
Initial analysis suggested the new Kido variant had date-limited functionality until 3 May 2009. This was Kaspersky's assessment of the malware's operational window.
Kaspersky Lab announced detection of a new Kido/Conficker variant and said it was conducting detailed analysis. The company also said its experts were working on a new version of the KKiller utility to handle the worm's latest functionality, and that its products detected the threat heuristically.
Kaspersky's analysis found the new Kido/Conficker variant again functioned as a worm and downloaded additional malware onto compromised systems. The payloads included the rogue antivirus FraudTool.Win32.SpywareProtect2009.s from websites in Ukraine and the Waledac email worm, detected as Email-Worm.Win32.Iksmas.atz.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcecontagiodump.blogspot.com
Open sourcekaspersky.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.