Researchers reported that the Mylobot botnet remains active on Windows systems and continues to evolve around two main malware components: mylobot-core and mylobot-proxy. The malware uses a shared packer-shellcode loader to unpack and inject later-stage payloads, with mylobot-core functioning largely as a downloader and mylobot-proxy converting infected devices into proxy nodes. Investigations found that proxy monetization appears to be the operation’s primary business model, with infected hosts feeding a broader residential-style proxy network.
Analysis also linked Mylobot infrastructure to the bhproxies proxy service, including overlap between bhproxies assets and newer Mylobot command-and-control domains. Researchers said mylobot-proxy had abandoned its earlier fake-DGA technique by 2022, while mylobot-core continued using encrypted fake-DGA domain infrastructure to retrieve follow-on payloads, especially the proxy module. Despite years of public exposure and relatively high detection rates, the botnet was assessed as still active and expanding, underscoring the persistence of criminal proxy-botnet operations.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
As of March 2023, Qianxin had captured a version of mylobot-proxy that used a unique software update mechanism. The malware also retained privileged instructions for downloading and executing additional payloads.
The Mylobot group updated the command-and-control infrastructure used by mylobot-proxy in late February 2023. Qianxin also noted overlap between newer Mylobot C2 infrastructure and bhproxies-linked assets.
An updated 2022 version of mylobot-proxy no longer used the earlier Fake-DGA approach for command-and-control. The report contrasts this with mylobot-core, which still used encrypted Fake-DGA domains.
Deep Instinct discovered the Windows-focused Mylobot botnet and gave it its name. The malware family was later observed operating multiple components including mylobot-proxy and mylobot-core.
Qianxin reported that the Mylobot group's Packer-Shellcode loader had not been significantly updated since 2017. The loader continued to unpack and inject later-stage payloads for the botnet.
BitSight previously linked Mylobot infrastructure to the bhproxies proxy service. Qianxin said its own analysis later reached the same conclusion.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 84 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.