Last seven days
- First activity
- Sep 5, 2026
- Last activity
- Sep 8, 2026
- Feed role
- C2
- Host form
- 0 IP / 2 hostnames
Glupteba is a long-running modular Windows malware family and botnet associated with cybercriminal operations since at least 2011.
Profile source: Mallory opens in a new tabGlupteba
Glupteba is a long-running modular Windows malware family and botnet associated with cybercriminal operations since at least 2011. It has functioned as a loader and backdoor platform used to deliver additional malicious components, including browser-stealing modules, cryptocurrency miners, proxy components, and router exploitation tooling. The malware has been distributed through multiple criminal channels, including malvertising, exploit-kit activity, pay-per-install ecosystems, fake freeware and cracked-software installers, and other deceptive download lures. It has also been observed as a payload delivered by other malware distribution services and loaders.
Glupteba is notable for combining stealth, persistence, and operational resilience. It establishes persistence through autorun mechanisms such as scheduled tasks and registry-based startup entries, profiles infected hosts, registers them with command-and-control infrastructure, and continuously polls for instructions. Multiple variants attempt to weaken host defenses by adding firewall allowances and Microsoft Defender exclusions, and some use privilege-escalation techniques such as the fodhelper UAC bypass followed by token-based elevation to SYSTEM. Several reports describe embedded or installed rootkit components used to hide files and processes and to interfere with security or analysis tools.
The malware supports broad post-compromise functionality. Documented capabilities include downloading and executing additional payloads, updating or uninstalling itself, capturing screenshots, uploading files, querying processes and services, and maintaining watcher components that relaunch failed modules. Glupteba has repeatedly been linked to credential and browser-data theft, including theft of passwords, cookies, browsing history, and account information from Chromium-based browsers. It has also been used to deploy cryptocurrency miners and to operate proxy infrastructure from infected hosts.
Glupteba has demonstrated lateral movement and network-expansion behavior. Windows-focused variants have used EternalBlue-related tooling to spread within local networks and scan for additional vulnerable systems. Other modules have targeted network appliances, especially MikroTik routers, including exploitation of CVE-2018-14847 to steal administrator credentials, create persistent scheduler tasks, and enable SOCKS proxying on compromised devices. This router-compromise capability has been linked by multiple researchers to the broader Mēris botnet ecosystem.
A distinctive feature of Glupteba is its resilient command-and-control recovery mechanism based on Bitcoin blockchain data. When primary infrastructure is disrupted, some variants can retrieve encrypted backup command-and-control information from Bitcoin transactions by parsing OP_RETURN data, making takedown efforts more difficult. This blockchain-assisted fallback has become one of the malware family's defining characteristics.
Glupteba has been tied to a broader criminal monetization ecosystem involving credential theft, residential proxy services, cryptojacking, spam operations, and malware delivery for third parties. Public reporting and legal action have linked the botnet to Russian cybercriminal operators and to services associated with proxying, advertising abuse, and stolen-account operations. The malware has infected systems globally at significant scale and remains notable for its modularity, resilience, and ability to bridge Windows compromises with abuse of network infrastructure.
C2 tracking
Derp observations, rolling seven-day window
Samples
8c19ea685326b082e051e3087cfd2c2027145e8f2e1f7cefbc13cf928d0a4796 24872b7ad94c53eb97a9da06c2b9502aadeb63212b86cd5d4872f75646b904b4 2618235b1678170e6563f0322804cf1a6a81224fdb3fc1c9823b7086a4ef6632 75534a3120f9f0c7c0a8c1572e43f478de698a51c61516b65408a755b8ad1072 a3eaa152ec08e57a6f75bc7925c25fc644f7bdeea9619299fa89e7b178b8a087 f79b155c0ece1d80fbd9e40b2a50d21b1fce0c0a5b6944e72b73313d0e5ea1d7 Reported operators
In our report, we’ve taken a deep dive into what makes the Glupteba malware distinctive. The core malware is, in essence, a dropper with extensive backdoor functionality...
UNCOVERING A BROAD CRIMINAL ECOSYSTEM POWERED BY ONE OF THE LARGEST BOTNETS, GLUPTEBA
Glupteba malware was first seen in the year 2014... Basically Glupteba malware are Remote Access (Backdoor) Trojans, capable of spreading using EternalBlue exploits.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Glupteba (botnet/backdoor avec rootkit)
Exploited software
MITRE ATT&CK
Reporting
Researchers linked the InstallCapital pay-per-install (PPI) operation to the delivery of multiple malware families through fake warez sites, a WordPress plugin, and a sprawling but centralized domain network. The installer fetched available offers from infrastructure referenced through Pastebin, then delivered second-stage payloads to victims who matched campaign conditions. Across 2017 to 2020, investigators observed more than 500 offers and nearly 200,000 domains tied to the operation, with testing showing distribution of Glupteba, Dreambot, and Legion Loader, the latter later dropping Raccoon Stealer. One of the payloads, Glupteba, was documented as a modular malware platform spread via malvertising that expanded beyond a botnet into credential theft, proxy abuse, and resilient command-and-control. Its newer variants stole browser cookies, history, and credentials from Chrome, Opera, and Yandex; exploited MikroTik routers via CVE-2018-14847 to steal administrator credentials and convert devices into SOCKS proxies; and used encrypted communications plus Bitcoin OP_RETURN data to recover updated C2 domains. The combined reporting shows how adware-style PPI distribution can serve as an initial access channel for more capable malware that steals data, hijacks network infrastructure, and maintains durable access.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.