logo

Dorkbot botnets disruption

ID: 8b0cd0ae-e725-53c3-bbec-d6f88a595883

STIX ID: report--8b0cd0ae-e725-53c3-bbec-d6f88a595883

Feed Name: CERT Polska

Threat Score
75/100

Date Published: 2015-12-04

Date Updated: 2026-04-19

Author: CERT Polska

...
...

CERT Polska reports on an international takedown and sinkholing operation against the long-running Dorkbot Windows botnet. Dorkbot steals credentials, disables security software, and acts as a dropper for other malware while propagating via Skype, social networks and USB; partners in the disruption included Microsoft, ESET and multiple law enforcement agencies, and estimates cite roughly 1 million global infections with relatively low impact in Poland. The report points users to removal tools and provides context on the infrastructure takeover and sinkholing activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.