logo

Lethic Botnet Returns, Uses "Realtek" Identifier

ID: 86f163df-eec5-53a7-8f98-b9dd8fa0e45e

STIX ID: report--86f163df-eec5-53a7-8f98-b9dd8fa0e45e

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

The report documents a Fall 2010 resurgence/variant of the Lethic (Ddox) spam botnet: two recent MD5-sampled binaries and ~91 additional samples include PE Version Info mimicking Realtek Semiconductor Corp. product data. Observed activity includes propagation from multiple IPs on changing ports, connections to newly registered C2 domains (izuhjsn.com, xkihjhx.com) and spam-sending via SMTP proxies/open-relays; the author notes that the Realtek string is not a cryptographic signature but a useful correlation artifact for attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.