DorkBot
DorkBot is a Windows malware family best known as a worm-operated botnet with backdoor and credential-theft functionality.
Profile source: Mallory opens in a new tabDorkBot
Family profile
DorkBot is a Windows malware family best known as a worm-operated botnet with backdoor and credential-theft functionality. It spread widely in the early-to-mid 2010s through instant messaging, removable drives, malicious websites, and social-media lures, especially Facebook messages and posts sent from compromised accounts. Campaigns also used deceptive files masquerading as images or other benign content to induce execution.
Once installed, DorkBot provided remote operators with control over infected systems through IRC-based command-and-control. Infected hosts could be instructed to download and execute additional malware, update themselves, send spam, participate in distributed denial-of-service activity, and support broader botnet operations. The malware was also used to steal credentials and other sensitive information, including through form grabbing and theft of cached or stored login data from browsers and network client applications. Reported theft targets included online-service and banking credentials.
DorkBot also exhibited defensive interference and user-manipulation behavior by blocking or redirecting access to selected websites, including security-related destinations, which hindered remediation and analysis. Variants have been associated with process-injection tradecraft, including use of the Early Bird APC injection technique to execute code in newly created suspended processes before normal thread startup reaches common monitoring points.
The family was tracked extensively by multiple security vendors and law-enforcement partners due to its scale and longevity. Microsoft reported substantial global infection volumes during 2015, and a joint disruption operation involving Microsoft and the FBI dismantled major DorkBot botnet infrastructure in December 2015. DorkBot remains notable as a socially propagated worm-bot that combined self-spread, backdoor access, credential theft, spam distribution, and DDoS enablement in a single criminal platform.
Capabilities
- Credential Theft
- Ddos
- Defense Evasion
- Exfiltration
- Post Exploitation
- Process Injection
MITRE ATT&CK