Corebot

First seen
2015-08-01 00:00:00
Malware type
trojan, credential-stealer, botnet
Family
Malware family
Last IoC activity
2026-06-27 03:32:05
Profile updated
2026-07-07 12:59:49

Targeted industries: financial-services

Context

Corebot is a trojan malware family known for stealing credentials. It primarily targets the financial services sector and has been observed being distributed through botnet campaigns.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Corebot_Auto (yara-rule)

Reports & references

  • CrowdStrike — Report Bosonspider (report)
  • CrowdStrike — Ecrime Ecosystem (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Corebot (report)
  • youtube.com — Watch (report)
  • malwarebreakdown.com — Re Details Malspam Downloads Corebot Banking Trojan (report)

External references