Gaudox

Malware type
loader, rootkit
Family
Malware family
Profile updated
2026-07-07 15:02:40

Context

Gaudox is a http loader, written in C/C++. The author claims to have put much effort into making this bot efficient and stable. Its rootkit functionality hides it in Windows Explorer (32bit only).

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Gaudox (yara-rule)
  • MALPEDIA_Win_Gaudox_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Gaudox (report)
  • nettoolz.blogspot.ch — Gaudox Http Bot 1101 Casm Ring3 Rootkit (report)

External references