logo

Malicious Life Podcast: The Mariposa Botnet

ID: 9fe8bdb4-491b-567a-b38f-2d8b36301c79

STIX ID: report--9fe8bdb4-491b-567a-b38f-2d8b36301c79

Feed Name: Cybereason Blog

Threat Score
78/100

Date Published: 2024-01-22

Date Updated: 2026-04-27

Author: Malicious Life Podcast

...
...

This report narrates the rise and takedown of the Mariposa botnet (driven by BFBOT), covering its creation and sale on the Darkode marketplace, diverse propagation methods (MSN, USB, P2P), use of Dynamic DNS for resilient C2, sinkholing and coordinated takedown by security firms and law enforcement, its large scale (~12.7M infected including Fortune 100 companies and major banks), data theft and DDoS abuse, and the arrests and prosecutions that followed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.