Asprox

Aliases: Aseljo, BadSrc

Malware type
botnet, credential-stealer, downloader
Family
Malware family
Profile updated
2026-07-07 14:45:36

Targeted industries: financial-services retail-and-hospitality

Context

Asprox is a botnet family known for its ability to carry out automated attacks on web applications, predominantly to steal credentials and send spam. It has been active since around 2008 and is often associated with large-scale email phishing campaigns.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Asprox_Auto (yara-rule)

Related threat objects

  • Asprox (infrastructure)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Asprox (report)
  • oalabs.openanalysis.net — Inside The New Asprox Kuluoz October 2013 January 2014 (report)
  • virusbulletin.com — Tracking 2012 Sasfis Campaign (report)
  • researchcenter.paloaltonetworks.com — Whats Next In Malware After Kuluoz (report)

External references