Conficker
MITRE ATT&CK: S0608 View on attack.mitre.org
Aliases: Kido, Downadup, downadup, traffic converter, Conficker
- First seen
- 2008-10-01 00:00:00
- Malware type
- worm, botnet
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 3488 (3300 malicious)
- Last IoC activity
- 2026-09-02 03:27:36
- Profile updated
- 2026-07-07 14:49:56
Targeted industries: energy-and-utilities government-and-public-sector
Context
Conficker is a computer worm first detected in October 2008 that targeted Microsoft Windows using the MS08-067 Windows vulnerability to spread. In 2016, a variant of Conficker made its way on computers and removable disk drives belonging to a nuclear power plant.
Recent IoC activity
3,305 malicious indicators in Maltiverse are attributed to Conficker (S0608). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | aksezhnx.net | 2026-09-02 | 1 |
| hostname | dyvqz.ws | 2026-09-02 | 1 |
| hostname | viomensx.ws | 2026-09-02 | 1 |
| hostname | shaqzxty.ws | 2026-09-02 | 1 |
| hostname | tsimfiipjm.ws | 2026-09-02 | 1 |
| hostname | fniceyca.ws | 2026-09-02 | 1 |
| hostname | wdahut.cn | 2026-09-02 | 1 |
| hostname | gzfijh.ws | 2026-09-02 | 1 |
| hostname | hitlkcojz.cn | 2026-09-02 | 1 |
| hostname | swmnu.biz | 2026-09-02 | 1 |
| hostname | zklxhunsqp.ws | 2026-09-01 | 1 |
| hostname | jimbftmvnl.ws | 2026-09-01 | 1 |
| hostname | qymmszsozvx.cn | 2026-09-01 | 1 |
| hostname | bbyurmkj.ws | 2026-09-01 | 1 |
| hostname | oiseejaavx.ws | 2026-09-01 | 1 |
| hostname | xnzsmxfygfz.cn | 2026-09-01 | 1 |
| hostname | jkuprpoaalu.ws | 2026-09-01 | 1 |
| hostname | pugpftp.net | 2026-09-01 | 1 |
| hostname | dkmirxob.ws | 2026-09-01 | 1 |
| hostname | mnqxawbgx.ws | 2026-09-01 | 1 |
Detection coverage
- 550 Sigma rules
Malware & tools used
- Modify Registry (attack-pattern)
- Windows Service (attack-pattern)
- System Time Discovery (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Domain Generation Algorithms (attack-pattern)
- Exploitation of Remote Services (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Network Service Discovery (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Replication Through Removable Media (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Loss of Productivity and Revenue (attack-pattern)
- Replication Through Removable Media (attack-pattern)
- Loss of Availability (attack-pattern)
Related threat objects
- Conficker (infrastructure)
Reports & references
- redcanary.com — Intelligence Insights January 2022 (report)
- web.archive.org — Blackhat Eu 2010 Carrera Silberman State Of Malware Slides (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Conficker (report)
- csl.sri.com — Index (report)
- github.com — Conficker.Md (report)
- kaspersky.com — 2009 Kaspersky Lab Analyses New Version Of Kido Conficker (report)
- sophos.com — Confickeranalysis (report)
- github.com — Cnfckr (report)
- minitool.com — Conficker Worm (report)
- contagiodump.blogspot.com — Win32Conficker (report)
- MITRE ATT&CK — S0608 (report)
- news.softpedia.com — On Chernobyl S 30Th Anniversary Malware Shuts Down German Nuclear Power Plant 503429.Shtml (report)
- web.archive.org — Conficker Worm (report)