Skip to content

Conficker

Conficker, also known as Downadup and Kido, is a Windows network worm first identified in 2008 that caused millions of infections globally, particularly affecting unpatched and legacy Windows environments.

Conficker

Family profile

Conficker, also known as Downadup and Kido, is a Windows network worm first identified in 2008 that caused millions of infections globally, particularly affecting unpatched and legacy Windows environments. Its principal propagation vector was exploitation of MS08-067, a remote code-execution vulnerability in the Windows Server service reachable over SMB/RPC. Variants also spread by brute-forcing weak credentials on SMB shares and by infecting removable media, enabling broad autonomous propagation within enterprise networks.

Conficker establishes persistence through Windows service and autorun mechanisms, modifies system and network settings, and can inject into Windows processes. It employs polymorphism, obfuscation, anti-analysis, anti-sandbox, and anti-virtualization measures, and has interfered with security products, update-related services, and security-related DNS resolution. The worm uses a domain-generation algorithm for command-and-control resilience; some variants additionally used peer-to-peer communications to receive updates and download further malware. Conficker is not reliably attributable to a publicly identified threat actor.

Capabilities

  • Brute Force
  • Defense Evasion
  • Lateral Movement
  • Persistence
  • Scanning

Samples

Recent samples

4 sandbox samples in the Derp library, newest 4 shown

Exploited software

Vulnerabilities linked to Conficker

1 CVEs

MITRE ATT&CK

Conficker in ATT&CK

47 distinct techniques

Reporting

Research mentioning Conficker