Skip to content

Glupteba

Glupteba is a long-running, modular Windows malware family associated with financially motivated cybercrime.

Profile source: Mallory opens in a new tab

Glupteba

Family profile

Glupteba is a long-running, modular Windows malware family associated with financially motivated cybercrime. First observed in the early 2010s, it evolved from a backdoor into a large botnet with multipurpose post-compromise functionality. Reported capabilities include downloading and installing additional payloads, credential and browser-data theft, abuse of infected systems for cryptomining and ad fraud, router exploitation, and broader botnet operations. Glupteba has also been observed in spam-bot contexts and in malware bundles delivered alongside stealers, loaders, ransomware, and miners.

A notable characteristic of Glupteba is its resilient command-and-control design. By 2019 it was using the Bitcoin blockchain as a backup mechanism to publish encrypted command-and-control update data, allowing operators to recover from infrastructure disruption more easily than with conventional domain-only schemes. Public reporting also noted disruption efforts against the botnet in 2021, followed by renewed activity thereafter.

Recent reporting describes Glupteba campaigns distributed through pay-per-install ecosystems, bundled installers, phishing, and cracked-software lures. Infection chains have included loaders such as PrivateLoader and SmokeLoader, and Glupteba has also appeared in broader malware-delivery networks tied to SEO-poisoned cracked-software sites. These campaigns have affected organizations and users across multiple regions and industries.

Glupteba is notable for advanced persistence and stealth tradecraft. In addition to conventional malware persistence, public research has documented a previously unreported UEFI bootkit capability used to modify the EFI System Partition and intervene in the Windows boot process before the operating system starts. The bootkit components were assessed as modified, recompiled derivatives of the open-source EfiGuard project, enabling the malware to disable Windows PatchGuard and Driver Signature Enforcement during boot to facilitate stealthier kernel-level activity and make remediation more difficult. Separate research has also identified Glupteba among real-world UEFI bootkits detectable through firmware-layer monitoring approaches.

Glupteba has repeatedly appeared as part of multi-malware criminal ecosystems and loader services, underscoring its role as both a standalone backdoor/botnet and a component of broader access monetization operations.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 26, 2026
Last activity
Jul 26, 2026
Feed role
C2
Host form
0 IP / 2 hostnames

Leading locations

  • US2

Leading providers

  • Amazon.com, Inc.2

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Operation STANDOFF

Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Glupteba (botnet/backdoor avec rootkit)

MITRE ATT&CK

Glupteba in ATT&CK

22 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.