Asprox
Aliases: Aseljo, BadSrc
- Malware type
- botnet, credential-stealer, downloader
- Family
- Malware family
- Profile updated
- 2026-07-07 14:45:36
Targeted industries: financial-services retail-and-hospitality
Context
Asprox is a botnet family known for its ability to carry out automated attacks on web applications, predominantly to steal credentials and send spam. It has been active since around 2008 and is often associated with large-scale email phishing campaigns.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Asprox_Auto (yara-rule)
Related threat objects
- Asprox (infrastructure)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Asprox (report)
- oalabs.openanalysis.net — Inside The New Asprox Kuluoz October 2013 January 2014 (report)
- virusbulletin.com — Tracking 2012 Sasfis Campaign (report)
- researchcenter.paloaltonetworks.com — Whats Next In Malware After Kuluoz (report)