logo

Evasive MyloBot botnet can take over enterprise devices to steal data, spread ransomware

ID: 83e4fd9f-8816-5fb4-812e-f18c2c13eddd

STIX ID: report--83e4fd9f-8816-5fb4-812e-f18c2c13eddd

Feed Name: Security Ledger

Threat Score
75/100

Date Published: 2018-06-19

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

MyloBot is a recently discovered, highly sophisticated botnet observed on a client device that achieves persistent, full system control by using anti-VM/sandbox/anti-debug techniques, memory-resident execution (reflective EXE), code injection and process hollowing; it disables Windows Defender, kills other malware, delays C2 activity for 14 days, and can download and execute secondary payloads (ransomware, banking trojans, data exfiltration), with indication that its command-and-control infrastructure is linked to dark web malware marketplaces, posing a significant enterprise risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.