Conficker

MITRE ATT&CK: S0608 View on attack.mitre.org

Aliases: Kido, Downadup, downadup, traffic converter, Conficker

First seen
2008-10-01 00:00:00
Malware type
worm, botnet
Family
Malware family
Operating systems
windows
Related IoCs
3488 (3300 malicious)
Last IoC activity
2026-09-02 03:27:36
Profile updated
2026-07-07 14:49:56

Targeted industries: energy-and-utilities government-and-public-sector

Context

Conficker is a computer worm first detected in October 2008 that targeted Microsoft Windows using the MS08-067 Windows vulnerability to spread. In 2016, a variant of Conficker made its way on computers and removable disk drives belonging to a nuclear power plant.

Recent IoC activity

3,305 malicious indicators in Maltiverse are attributed to Conficker (S0608). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname aksezhnx.net 2026-09-02 1
hostname dyvqz.ws 2026-09-02 1
hostname viomensx.ws 2026-09-02 1
hostname shaqzxty.ws 2026-09-02 1
hostname tsimfiipjm.ws 2026-09-02 1
hostname fniceyca.ws 2026-09-02 1
hostname wdahut.cn 2026-09-02 1
hostname gzfijh.ws 2026-09-02 1
hostname hitlkcojz.cn 2026-09-02 1
hostname swmnu.biz 2026-09-02 1
hostname zklxhunsqp.ws 2026-09-01 1
hostname jimbftmvnl.ws 2026-09-01 1
hostname qymmszsozvx.cn 2026-09-01 1
hostname bbyurmkj.ws 2026-09-01 1
hostname oiseejaavx.ws 2026-09-01 1
hostname xnzsmxfygfz.cn 2026-09-01 1
hostname jkuprpoaalu.ws 2026-09-01 1
hostname pugpftp.net 2026-09-01 1
hostname dkmirxob.ws 2026-09-01 1
hostname mnqxawbgx.ws 2026-09-01 1

Detection coverage

  • 550 Sigma rules

Malware & tools used

  • Modify Registry (attack-pattern)
  • Windows Service (attack-pattern)
  • System Time Discovery (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Domain Generation Algorithms (attack-pattern)
  • Exploitation of Remote Services (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Replication Through Removable Media (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Loss of Productivity and Revenue (attack-pattern)
  • Replication Through Removable Media (attack-pattern)
  • Loss of Availability (attack-pattern)

Related threat objects

  • Conficker (infrastructure)

Reports & references

  • redcanary.com — Intelligence Insights January 2022 (report)
  • web.archive.org — Blackhat Eu 2010 Carrera Silberman State Of Malware Slides (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Conficker (report)
  • csl.sri.com — Index (report)
  • github.com — Conficker.Md (report)
  • kaspersky.com — 2009 Kaspersky Lab Analyses New Version Of Kido Conficker (report)
  • sophos.com — Confickeranalysis (report)
  • github.com — Cnfckr (report)
  • minitool.com — Conficker Worm (report)
  • contagiodump.blogspot.com — Win32Conficker (report)
  • MITRE ATT&CK — S0608 (report)
  • news.softpedia.com — On Chernobyl S 30Th Anniversary Malware Shuts Down German Nuclear Power Plant 503429.Shtml (report)
  • web.archive.org — Conficker Worm (report)

External references