logo

Trojan Monkif Is Still An Active And Consistent Botnet Threat

ID: c82cfab5-7243-540e-af9f-a723b9330aab

STIX ID: report--c82cfab5-7243-540e-af9f-a723b9330aab

Feed Name: Zscaler Security Research Blog

Threat Score
68/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report describes active Monkif Trojan botnet activity (Q1 2010): the malware fetches encoded commands hidden in JPEG images from a small set of C2 servers (notably 88.80.7.152 and several click*/*.biz domains), generates unique randomized HTTP requests to evade IDS/IPS, installs a BHO, and downloads additional malware; sample C2 URLs, encoded command examples, and a Virustotal result showing zero AV detections are provided, and readers are advised to block listed domains and ensure protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.