Glupteba is a long-running modular Windows malware family and botnet associated with cybercriminal operations since at least 2011. It has functioned as a loader and backdoor platform used to deliver additional malicious components, including browser-stealing modules, cryptocurrency miners, proxy components, and router exploitation tooling. The malware has been distributed through multiple criminal channels, including malvertising, exploit-kit activity, pay-per-install ecosystems, fake freeware and cracked-software installers, and other deceptive download lures. It has also been observed as a payload delivered by other malware distribution services and loaders.
Glupteba is notable for combining stealth, persistence, and operational resilience. It establishes persistence through autorun mechanisms such as scheduled tasks and registry-based startup entries, profiles infected hosts, registers them with command-and-control infrastructure, and continuously polls for instructions. Multiple variants attempt to weaken host defenses by adding firewall allowances and Microsoft Defender exclusions, and some use privilege-escalation techniques such as the fodhelper UAC bypass followed by token-based elevation to SYSTEM. Several reports describe embedded or installed rootkit components used to hide files and processes and to interfere with security or analysis tools.
The malware supports broad post-compromise functionality. Documented capabilities include downloading and executing additional payloads, updating or uninstalling itself, capturing screenshots, uploading files, querying processes and services, and maintaining watcher components that relaunch failed modules. Glupteba has repeatedly been linked to credential and browser-data theft, including theft of passwords, cookies, browsing history, and account information from Chromium-based browsers. It has also been used to deploy cryptocurrency miners and to operate proxy infrastructure from infected hosts.
Glupteba has demonstrated lateral movement and network-expansion behavior. Windows-focused variants have used EternalBlue-related tooling to spread within local networks and scan for additional vulnerable systems. Other modules have targeted network appliances, especially MikroTik routers, including exploitation of CVE-2018-14847 to steal administrator credentials, create persistent scheduler tasks, and enable SOCKS proxying on compromised devices. This router-compromise capability has been linked by multiple researchers to the broader Mēris botnet ecosystem.
A distinctive feature of Glupteba is its resilient command-and-control recovery mechanism based on Bitcoin blockchain data. When primary infrastructure is disrupted, some variants can retrieve encrypted backup command-and-control information from Bitcoin transactions by parsing OP_RETURN data, making takedown efforts more difficult. This blockchain-assisted fallback has become one of the malware family's defining characteristics.
Glupteba has been tied to a broader criminal monetization ecosystem involving credential theft, residential proxy services, cryptojacking, spam operations, and malware delivery for third parties. Public reporting and legal action have linked the botnet to Russian cybercriminal operators and to services associated with proxying, advertising abuse, and stolen-account operations. The malware has infected systems globally at significant scale and remains notable for its modularity, resilience, and ability to bridge Windows compromises with abuse of network infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
We recently caught a malvertising attack distributing the malware Glupteba... After looking into the recent variant of the Glupteba dropper delivered from the malvertising attack, we found that the dropper downloaded two undocumented components aside from the Glupteba malware...
Glupteba malware was first seen in the year 2014... Basically Glupteba malware are Remote Access (Backdoor) Trojans, capable of spreading using EternalBlue exploits.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In our report, we’ve taken a deep dive into what makes the Glupteba malware distinctive. The core malware is, in essence, a dropper with extensive backdoor functionality...
UNCOVERING A BROAD CRIMINAL ECOSYSTEM POWERED BY ONE OF THE LARGEST BOTNETS, GLUPTEBA
Glupteba malware was first seen in the year 2014... Basically Glupteba malware are Remote Access (Backdoor) Trojans, capable of spreading using EternalBlue exploits.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Glupteba (botnet/backdoor avec rootkit)
39 distinct techniques documented for this family, organized by ATT&CK tactic.
Once credentials are successfully obtained, a task is added to the scheduler of the router... The router exploiter component scheduled a task named “U6” on compromised routers for command and control.
Once credentials are successfully obtained, a task is added to the scheduler of the router... The router exploiter component scheduled a task named “U6” on compromised routers for command and control.
...были найдены определенно подозрительные задачи... Вторая с использованием легитимной программы certutil.exe и переданного параметра urlcache загружает... app.exe ... после чего обеспечивает его запуск.
It allows the attackers to grab the administrator’s credentials from unpatched routers.
Once credentials are successfully obtained, a task is added to the scheduler of the router... The router exploiter component scheduled a task named “U6” on compromised routers for command and control.
...были найдены определенно подозрительные задачи... Вторая с использованием легитимной программы certutil.exe и переданного параметра urlcache загружает... app.exe ... после чего обеспечивает его запуск.
If process is not elevated, it tries to exploit the fodhelper method to get it elevated. If it is elevated but not running as a SYSTEM user, it uses the “Run as Trusted Installer” method, likely inspired by this code, which uses a stolen winlogon process token to run process as SYSTEM.
It allows the attackers to grab the administrator’s credentials from unpatched routers.
it uses the “Run as Trusted Installer” method... which uses a stolen winlogon process token to run process as SYSTEM
The main dropper binary has embedded a few rootkit drivers used for hiding files and processes
update Terminate and remove current version, replace with new version cleanup Uninstall
It allows the attackers to grab the administrator’s credentials from unpatched routers.
it uses the “Run as Trusted Installer” method... which uses a stolen winlogon process token to run process as SYSTEM
...с использованием легитимной программы certutil.exe и переданного параметра urlcache загружает с ресурса hxxps://fotamene[.]com/app/app.exe... Обратите внимание, что в созданной задаче применяется техника Living-off-the-Land ... с использованием certutil.exe.
...проверка окружения на предмет виртуализации: Открытие \\.\VBoxMiniRdrDN; Проверка имени процессора: Nehalem; Проверка запущенных процессов: VBoxTray.exe, VBoxService.exe... vmtoolsd.exe.
...а также брутфорса серверов по протоколу SSH... Брутфорсеры паролей SSH. Используют очень небольшой словарь наиболее популярных слабых паролей;
It looks into the default gateway of the victim’s network... Once the component successfully connects to the device listening on port 8291
sendParentProcesses acquires machine_guid from the registry... and names of parent processes.
The dropper first initializes ‘config information’ by acquiring current application information, operating information, hardware information
were identified as using the EternalBlue exploit to move into local networks and run Monero (XMR) cryptocurrency miners | it then attempts to exploit the device with the CVE-2018-14847 vulnerability, which affects the RouterOS system used on MikroTik routers.
the response contains the session and the port that Glupteba will connect to for retrieval of the proxying jobs | When launched, Glupteba sends the same beacon to its C&C... Beacon sent to the C&C: GET /stat?... HTTP/1.0
...запросы к /api/cdn на C2... с CDN загружается и запускается указанный исполняемый файл...
A compromised router will be configured as a SOCKS proxy to relay malicious traffic
We saw a remote server establish SMTP connections to different mail servers through the SOCKS proxy of compromised routers.
the dropper downloaded two undocumented components aside from the Glupteba malware
Модуль, «общающейся» с сервером злоумышленника по протоколу WebRTC...
263 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet component included in the STANDOFF package, contributing to persistent access and proxy/relay-style abuse of infected systems.
Mentioned only in appendix literature as linked to a proxy service.
Botnet/backdoor malware with rootkit capabilities deployed in the campaign bundle.
A botnet noted for using the Bitcoin blockchain OP_RETURN field to store encrypted backup C2 domains, enabling resilient command-and-control recovery after disruption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.