Last seven days
- First activity
- Aug 1, 2026
- Last activity
- Aug 1, 2026
- Feed role
- C2
- Host form
- 0 IP / 2 hostnames
Glupteba is a long-running, modular Windows malware family associated with financially motivated cybercrime.
Profile source: Mallory opens in a new tabGlupteba
Glupteba is a long-running, modular Windows malware family associated with financially motivated cybercrime. First observed in the early 2010s as a backdoor, it evolved into a multipurpose botnet used for persistent access, payload delivery, credential and browser-data theft, cryptomining, ad fraud, and related post-compromise monetization. Reported modules and campaigns have also included browser-stealing functionality and router-exploitation capability.
Glupteba is commonly distributed through large-scale criminal delivery ecosystems, including pay-per-install operations, bundled malware installers, phishing, and cracked-software lures promoted through SEO-poisoned websites. It has frequently appeared alongside other commodity malware families in multi-payload infection chains, where loaders such as PrivateLoader or SmokeLoader deliver Glupteba together with stealers, miners, and additional malware.
A notable characteristic of Glupteba is its resilient command-and-control design. By 2019, operators were using the Bitcoin blockchain as a backup mechanism to publish encrypted command-and-control update data, allowing the botnet to recover from infrastructure disruption. Public reporting also notes that Glupteba reemerged after major disruption efforts by rotating elements of this blockchain-backed recovery mechanism.
Recent reporting describes Glupteba as incorporating an advanced UEFI bootkit capability for stealthy persistence on Windows systems. This capability modifies the EFI System Partition so malicious boot components execute before the operating system starts. The bootkit has been linked to modified, recompiled components derived from the open-source EfiGuard project, enabling the malware to interfere with Windows boot protections and disable Driver Signature Enforcement and PatchGuard at boot time. This gives Glupteba unusually durable persistence and facilitates stealthy kernel-level follow-on activity. No confirmed Secure Boot bypass has been established for this activity.
Glupteba has been observed globally across multiple industries and regions in broad criminal campaigns rather than a single narrowly targeted vertical. Its role in infection chains ranges from maintaining access and expanding botnet scale to enabling credential theft, cryptomining, and delivery of additional payloads. The combination of modularity, resilient command-and-control, and firmware-level persistence makes Glupteba one of the more sophisticated long-running cybercrime malware families.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Glupteba (botnet/backdoor avec rootkit)
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.