Skip to content

DorkBot

Dorkbot is a Windows malware family best known as a worm and IRC-controlled bot that spread widely through instant messaging, social media, removable media, and malicious links on websites.

Profile source: Mallory opens in a new tab

DorkBot

Family profile

Dorkbot is a Windows malware family best known as a worm and IRC-controlled bot that spread widely through instant messaging, social media, removable media, and malicious links on websites. It propagated aggressively through Facebook and other messaging channels using social-engineering lures, and also spread via USB drives, making it effective in both consumer and enterprise environments. Related activity included deceptive links masquerading as images or other benign content to induce execution.

Once installed, Dorkbot provided backdoor access to infected systems and connected to command-and-control infrastructure over IRC. Operators could use infected hosts to download and execute additional payloads, update the malware, distribute spam, and participate in distributed denial-of-service activity. The malware was also used for credential theft, including harvesting login data through form grabbing and theft of cached or stored credentials from browsers and network client applications. Reported theft targets included online and banking-related credentials.

Dorkbot also exhibited defensive interference and traffic manipulation behavior, including blocking or redirecting users away from security-related websites. Variants and associated samples have been observed using process injection techniques, including Early Bird APC injection, as part of post-compromise execution and evasion tradecraft. The family was sufficiently prevalent that Microsoft reported large-scale monthly detections in 2015, and a joint disruption operation by Microsoft and law enforcement targeted the botnet infrastructure in December 2015.

Dorkbot is commonly referred to as Backdoor.IRCBot.Dorkbot in vendor naming, reflecting its dual role as a worm and IRC bot with backdoor functionality. Its historical impact stems from its combination of social propagation, credential theft, modular payload delivery, and botnet monetization through spam and DDoS operations.

Capabilities

  • Credential Theft
  • Ddos
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Post Exploitation
  • Process Injection

MITRE ATT&CK

DorkBot in ATT&CK

11 distinct techniques

Reporting

Research mentioning DorkBot

Jul 31
Sysdig

Threat news: TeamTNT stealing credentials using EC2 Instance Metadata | Sysdig

TeamTNT continued to evolve from a Linux-focused cryptojacking group into a broad cloud threat actor targeting exposed Redis, Docker, Kubernetes, Jupyter, Hadoop, PostgreSQL, Tomcat, Nginx, SSH, and other internet-facing services. Researchers tied the group to worm-like campaigns that rapidly scanned for vulnerable hosts, deployed XMRig miners, dropped Tsunami-based IRC bots including DDoS-capable variants, and used malicious container images on Docker Hub to spread payloads at scale. One TeamTNT-linked Docker Hub account reportedly served images pulled more than 150,000 times, while later campaigns showed the group abusing public registries, compromised accounts, and cloud-native tooling to infect newly exposed systems and report them back to command-and-control infrastructure. Across these operations, TeamTNT consistently paired monetization with aggressive credential theft and stealth. Investigations found the group harvesting AWS, Azure, GCP, Kubernetes, Git, NPM, Grafana, database, and storage secrets; stealing SSH keys and host data; and using tools such as Weave Scope, Peirates, BotB, MimiPenguin, Mimipy, tmate, and Gsocket to expand access and persistence. Analysts also documented detection evasion through log wiping, process hiding, LD_PRELOAD userland rootkits, the Diamorphine kernel rootkit, privileged containers with restart policies, and even disabling runc to lock out rival attackers, underscoring TeamTNT’s shift from opportunistic mining to sustained compromise of cloud and container environments.

Apr 14
Mitre Attack Website

Matrix - Enterprise - Containers | MITRE ATT&CK®

Jan 1
Intezer

Abusing Legitimate Cloud Monitoring Tools for Cyber Attacks - Intezer

Jan 1
Intezer

TeamTNT Cryptomining Explosion 🧨 - Intezer

Sep 11
Group Ib

Storm clouds on the horizon: Resurgence of TeamTNT? | Group-IB Blog

Jul 13
Aquasec Other

TeamTNT Reemerged with New Aggressive Cloud Campaign

Sep 15
Aquasec

Threat Alert: New Malware in the Cloud By TeamTNT

Sep 12
Trend Micro Research

Security Breaks: TeamTNT’s DockerHub Credentials Leak | Trend Micro (US)

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.