Conficker
Conficker, also known as Downadup and Kido, is a Windows network worm first identified in 2008 that caused millions of infections globally, particularly affecting unpatched and legacy Windows environments.
Conficker
Family profile
Conficker, also known as Downadup and Kido, is a Windows network worm first identified in 2008 that caused millions of infections globally, particularly affecting unpatched and legacy Windows environments. Its principal propagation vector was exploitation of MS08-067, a remote code-execution vulnerability in the Windows Server service reachable over SMB/RPC. Variants also spread by brute-forcing weak credentials on SMB shares and by infecting removable media, enabling broad autonomous propagation within enterprise networks.
Conficker establishes persistence through Windows service and autorun mechanisms, modifies system and network settings, and can inject into Windows processes. It employs polymorphism, obfuscation, anti-analysis, anti-sandbox, and anti-virtualization measures, and has interfered with security products, update-related services, and security-related DNS resolution. The worm uses a domain-generation algorithm for command-and-control resilience; some variants additionally used peer-to-peer communications to receive updates and download further malware. Conficker is not reliably attributable to a publicly identified threat actor.
Capabilities
- Brute Force
- Defense Evasion
- Lateral Movement
- Persistence
- Scanning
Samples
Recent samples
4 sandbox samples in the Derp library, newest 4 shown
5ee22794320d8e1e0310f3dcfa58b65e6d9293d9e012bfad4231cd6ae77306e8 cff54b92ce353e56fda1c6df77950979c96e06e22b77e99ba39b6c8a36d7a53d cf82e064ba006444c8a8227da4ae3e688facbcaadf88f2da938726aa24f206d5 9af727864495933556e45bfaa3a550b0436f7b66f6efaf5cd8400137a0b100f7 Exploited software
Vulnerabilities linked to Conficker
1 CVEsMITRE ATT&CK
Conficker in ATT&CK
47 distinct techniquesReporting
Research mentioning Conficker
CVE-2026-62781 - RPC Runtime Library Remote Code Execution Vulnerability
Microsoft disclosed CVE-2026-62781, a high-severity remote code execution flaw in the Windows RPC Runtime Library that allows an unauthenticated attacker to execute code over the network. The heap-based buffer overflow, tracked as CWE-122 and scored CVSS 8.1, affects a broad range of Windows client and server platforms, including Windows 10, Windows 11, and Windows Server 2012, 2016, 2019, 2022, and 2025, according to the CVE entry and Microsoft advisory. The exposure is notable because exploitation of remote services has repeatedly enabled rapid lateral movement and internal propagation across Windows environments. MITRE ATT&CK maps this activity to T1210, citing past abuse of SMB, Netlogon, RPC, and Print Spooler flaws by threats such as WannaCry, NotPetya, TrickBot, Conficker, and multiple intrusion groups; Splunk has also tied remote-service exploitation detections to the same technique in prior RCE-related content. Security teams are likely to treat the new RPC flaw as a priority patching issue given its network-reachable nature and the history of Windows remote-service vulnerabilities being used for enterprise-wide spread.