Skip to content

Glupteba

Glupteba is a long-running modular Windows malware family and botnet associated with cybercriminal operations since at least 2011.

Profile source: Mallory opens in a new tab

Glupteba

Family profile

Glupteba is a long-running modular Windows malware family and botnet associated with cybercriminal operations since at least 2011. It has functioned as a loader and backdoor platform used to deliver additional malicious components, including browser-stealing modules, cryptocurrency miners, proxy components, and router exploitation tooling. The malware has been distributed through multiple criminal channels, including malvertising, exploit-kit activity, pay-per-install ecosystems, fake freeware and cracked-software installers, and other deceptive download lures. It has also been observed as a payload delivered by other malware distribution services and loaders.

Glupteba is notable for combining stealth, persistence, and operational resilience. It establishes persistence through autorun mechanisms such as scheduled tasks and registry-based startup entries, profiles infected hosts, registers them with command-and-control infrastructure, and continuously polls for instructions. Multiple variants attempt to weaken host defenses by adding firewall allowances and Microsoft Defender exclusions, and some use privilege-escalation techniques such as the fodhelper UAC bypass followed by token-based elevation to SYSTEM. Several reports describe embedded or installed rootkit components used to hide files and processes and to interfere with security or analysis tools.

The malware supports broad post-compromise functionality. Documented capabilities include downloading and executing additional payloads, updating or uninstalling itself, capturing screenshots, uploading files, querying processes and services, and maintaining watcher components that relaunch failed modules. Glupteba has repeatedly been linked to credential and browser-data theft, including theft of passwords, cookies, browsing history, and account information from Chromium-based browsers. It has also been used to deploy cryptocurrency miners and to operate proxy infrastructure from infected hosts.

Glupteba has demonstrated lateral movement and network-expansion behavior. Windows-focused variants have used EternalBlue-related tooling to spread within local networks and scan for additional vulnerable systems. Other modules have targeted network appliances, especially MikroTik routers, including exploitation of CVE-2018-14847 to steal administrator credentials, create persistent scheduler tasks, and enable SOCKS proxying on compromised devices. This router-compromise capability has been linked by multiple researchers to the broader Mēris botnet ecosystem.

A distinctive feature of Glupteba is its resilient command-and-control recovery mechanism based on Bitcoin blockchain data. When primary infrastructure is disrupted, some variants can retrieve encrypted backup command-and-control information from Bitcoin transactions by parsing OP_RETURN data, making takedown efforts more difficult. This blockchain-assisted fallback has become one of the malware family's defining characteristics.

Glupteba has been tied to a broader criminal monetization ecosystem involving credential theft, residential proxy services, cryptojacking, spam operations, and malware delivery for third parties. Public reporting and legal action have linked the botnet to Russian cybercriminal operators and to services associated with proxying, advertising abuse, and stolen-account operations. The malware has infected systems globally at significant scale and remains notable for its modularity, resilience, and ability to bridge Windows compromises with abuse of network infrastructure.

Capabilities

  • Brute Force
  • Byovd
  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance
  • Scanning
  • Session Hijacking
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 5, 2026
Last activity
Sep 8, 2026
Feed role
C2
Host form
0 IP / 2 hostnames

Leading locations

  • CA1
  • US1

Leading providers

  • Amazon.com, Inc.1
  • Team Internet AG1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
Shadow Brokers

In our report, we’ve taken a deep dive into what makes the Glupteba malware distinctive. The core malware is, in essence, a dropper with extensive backdoor functionality...

Voltron

UNCOVERING A BROAD CRIMINAL ECOSYSTEM POWERED BY ONE OF THE LARGEST BOTNETS, GLUPTEBA

Equation Group

Glupteba malware was first seen in the year 2014... Basically Glupteba malware are Remote Access (Backdoor) Trojans, capable of spreading using EternalBlue exploits.

Operation STANDOFF

Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Glupteba (botnet/backdoor avec rootkit)

Exploited software

Vulnerabilities linked to Glupteba

2 CVEs

MITRE ATT&CK

Glupteba in ATT&CK

69 distinct techniques

Techniques

69 techniques
T1071 Application Layer Protocol T1562 Impair Defenses T1210 Exploitation of Remote Services T1568 Dynamic Resolution T1057 Process Discovery T1053 Scheduled Task/Job T1105 Ingress Tool Transfer T1046 Network Service Discovery T1564 Hide Artifacts T1584.005 Botnet T1573 Encrypted Channel T1041 Exfiltration Over C2 Channel T1134 Access Token Manipulation T1548.002 Bypass User Account Control T1583 Acquire Infrastructure T1539 Steal Web Session Cookie T1014 Rootkit T1090 Proxy T1082 System Information Discovery T1555 Credentials from Password Stores T1068 Exploitation for Privilege Escalation T1112 Modify Registry T1078 Valid Accounts T1113 Screen Capture T1070 Indicator Removal T1095 Non-Application Layer Protocol T1059.003 Windows Command Shell T1036 Masquerading T1053.005 Scheduled Task T1071.001 Web Protocols T1190 Exploit Public-Facing Application T1219 Remote Access Tools T1110 Brute Force T1497.001 System Checks T1649 Steal or Forge Authentication Certificates T1218.010 Regsvr32 T1547.001 Registry Run Keys / Startup Folder T1071.004 DNS T1497 Virtualization/Sandbox Evasion T1090.002 External Proxy T1204 User Execution T1583.008 Malvertising T1027 Obfuscated Files or Information T1048 Exfiltration Over Alternative Protocol T1090.003 Multi-hop Proxy T1189 Drive-by Compromise T1496 Resource Hijacking T1059 Command and Scripting Interpreter T1505.003 Web Shell T1204.002 Malicious File T1566 Phishing T1587.001 Malware T1110.003 Password Spraying T1486 Data Encrypted for Impact T1498 Network Denial of Service T1055 Process Injection T1008 Fallback Channels T1546 Event Triggered Execution T1490 Inhibit System Recovery T1027.010 Command Obfuscation T1570 Lateral Tool Transfer T1033 System Owner/User Discovery T1203 Exploitation for Client Execution T1543.003 Windows Service T1562.001 Disable or Modify Tools T1608.006 SEO Poisoning T1542.003 Bootkit T1222.001 Windows File and Directory Permissions Modification T1542.001 System Firmware

Reporting

Research mentioning Glupteba

Feb 9
Medium Csis Techblog

InstallCapital - When AdWare Becomes Pay-per-Install Cyber-Crime. | by Benoit ANCEL | CSIS TechBlog | Medium

Researchers linked the InstallCapital pay-per-install (PPI) operation to the delivery of multiple malware families through fake warez sites, a WordPress plugin, and a sprawling but centralized domain network. The installer fetched available offers from infrastructure referenced through Pastebin, then delivered second-stage payloads to victims who matched campaign conditions. Across 2017 to 2020, investigators observed more than 500 offers and nearly 200,000 domains tied to the operation, with testing showing distribution of Glupteba, Dreambot, and Legion Loader, the latter later dropping Raccoon Stealer. One of the payloads, Glupteba, was documented as a modular malware platform spread via malvertising that expanded beyond a botnet into credential theft, proxy abuse, and resilient command-and-control. Its newer variants stole browser cookies, history, and credentials from Chrome, Opera, and Yandex; exploited MikroTik routers via CVE-2018-14847 to steal administrator credentials and convert devices into SOCKS proxies; and used encrypted communications plus Bitcoin OP_RETURN data to recover updated C2 domains. The combined reporting shows how adware-style PPI distribution can serve as an initial access channel for more capable malware that steals data, hijacks network infrastructure, and maintains durable access.

Sep 4
Trend Micro Blog Historic

Glupteba Hits Routers and Updates C&C Servers | Trend Micro (US)

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.