Glupteba is a modular Windows backdoor and botnet malware family used for credential theft, cryptocurrency mining, malicious proxy services, and delivery of additional malware. Its components support downloading and executing payloads, uploading files, capturing screenshots, querying processes, collecting system information, and controlling cryptocurrency miners. Browser-stealing modules extract passwords, account information, browsing history, and session cookies from Chrome, Opera, and Yandex. Compromised systems also relay spam and other abusive traffic through proxy services.
Glupteba has been distributed through malvertising, exploit kits, installers masquerading as pirated commercial software, and pay-per-install networks, including InstallCapital and PrivateLoader. It has also been delivered as a downstream payload of MosaicLoader. Historically associated with Operation Windigo's exploit-kit and spam infrastructure, Glupteba subsequently developed into a separate botnet. Infections have been observed worldwide on personal computers and within corporate networks.
Glupteba establishes persistence through scheduled tasks, registry autorun entries, and monitoring components that restart failed or removed modules. It bypasses Windows User Account Control through execution hijacking and uses token manipulation to obtain SYSTEM privileges. Its defense-evasion mechanisms include sandbox and virtualization checks, Microsoft Defender exclusions, interference with security and analysis tools, and kernel rootkit drivers that conceal files and processes. It also applies restrictive service permissions to prevent administrators from stopping protective components.
The malware spreads laterally through EternalBlue exploitation of CVE-2017-0144 and deploys modules for network scanning and SSH brute-force attacks. A MikroTik-focused component exploits CVE-2018-14847 to steal router administrator credentials, establish recurring command execution, and configure compromised routers as SOCKS proxies. Glupteba maintains resilient command and control by retrieving and decrypting infrastructure information embedded in Bitcoin OP_RETURN transaction data, allowing infected systems to locate replacement servers after conventional infrastructure is disrupted.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
We recently caught a malvertising attack distributing the malware Glupteba... After looking into the recent variant of the Glupteba dropper delivered from the malvertising attack, we found that the dropper downloaded two undocumented components aside from the Glupteba malware...
Glupteba malware was first seen in the year 2014... Basically Glupteba malware are Remote Access (Backdoor) Trojans, capable of spreading using EternalBlue exploits.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In our report, we’ve taken a deep dive into what makes the Glupteba malware distinctive. The core malware is, in essence, a dropper with extensive backdoor functionality...
UNCOVERING A BROAD CRIMINAL ECOSYSTEM POWERED BY ONE OF THE LARGEST BOTNETS, GLUPTEBA
Glupteba malware was first seen in the year 2014... Basically Glupteba malware are Remote Access (Backdoor) Trojans, capable of spreading using EternalBlue exploits.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : Glupteba (botnet/backdoor avec rootkit)
39 distinct techniques documented for this family, organized by ATT&CK tactic.
Once credentials are successfully obtained, a task is added to the scheduler of the router... The router exploiter component scheduled a task named “U6” on compromised routers for command and control.
Once credentials are successfully obtained, a task is added to the scheduler of the router... The router exploiter component scheduled a task named “U6” on compromised routers for command and control.
...были найдены определенно подозрительные задачи... Вторая с использованием легитимной программы certutil.exe и переданного параметра urlcache загружает... app.exe ... после чего обеспечивает его запуск.
It allows the attackers to grab the administrator’s credentials from unpatched routers.
Once credentials are successfully obtained, a task is added to the scheduler of the router... The router exploiter component scheduled a task named “U6” on compromised routers for command and control.
...были найдены определенно подозрительные задачи... Вторая с использованием легитимной программы certutil.exe и переданного параметра urlcache загружает... app.exe ... после чего обеспечивает его запуск.
If process is not elevated, it tries to exploit the fodhelper method to get it elevated. If it is elevated but not running as a SYSTEM user, it uses the “Run as Trusted Installer” method, likely inspired by this code, which uses a stolen winlogon process token to run process as SYSTEM.
It allows the attackers to grab the administrator’s credentials from unpatched routers.
it uses the “Run as Trusted Installer” method... which uses a stolen winlogon process token to run process as SYSTEM
The main dropper binary has embedded a few rootkit drivers used for hiding files and processes
update Terminate and remove current version, replace with new version cleanup Uninstall
It allows the attackers to grab the administrator’s credentials from unpatched routers.
it uses the “Run as Trusted Installer” method... which uses a stolen winlogon process token to run process as SYSTEM
...с использованием легитимной программы certutil.exe и переданного параметра urlcache загружает с ресурса hxxps://fotamene[.]com/app/app.exe... Обратите внимание, что в созданной задаче применяется техника Living-off-the-Land ... с использованием certutil.exe.
...а также брутфорса серверов по протоколу SSH... Брутфорсеры паролей SSH. Используют очень небольшой словарь наиболее популярных слабых паролей;
It looks into the default gateway of the victim’s network... Once the component successfully connects to the device listening on port 8291
sendParentProcesses acquires machine_guid from the registry... and names of parent processes.
were identified as using the EternalBlue exploit to move into local networks and run Monero (XMR) cryptocurrency miners | it then attempts to exploit the device with the CVE-2018-14847 vulnerability, which affects the RouterOS system used on MikroTik routers.
the response contains the session and the port that Glupteba will connect to for retrieval of the proxying jobs | When launched, Glupteba sends the same beacon to its C&C... Beacon sent to the C&C: GET /stat?... HTTP/1.0
...запросы к /api/cdn на C2... с CDN загружается и запускается указанный исполняемый файл...
A compromised router will be configured as a SOCKS proxy to relay malicious traffic
We saw a remote server establish SMTP connections to different mail servers through the SOCKS proxy of compromised routers.
“The technique, named Blockchain Dead Drops (BDD), stores payloads in on-chain transactions and smart contracts where infected devices can retrieve them on demand.” The article explicitly maps it to “T1102.001 (Web Service: Dead Drop Resolver).”
« Blockchain Dead Drops (BDD) ... stocker des instructions de malware ou des configurations C2 sur des blockchains publiques » ; « Smart contracts sur Polygon utilisés comme résolveurs C2 ».
the dropper downloaded two undocumented components aside from the Glupteba malware
Модуль, «общающейся» с сервером злоумышленника по протоколу WebRTC...
271 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
53 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptomining botnet cited as using Bitcoin OP_RETURN transaction data to store malicious information.
Botnet described as using Bitcoin OP_RETURN data to store command-and-control information.
Cryptomining botnet whose operators used Bitcoin OP_RETURN transaction data to store malicious information.
A botnet component included in the STANDOFF package, contributing to persistent access and proxy/relay-style abuse of infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.