HtBot

First seen
2011-01-01 00:00:00
Malware type
botnet, ddos
Family
Malware family
Profile updated
2026-07-07 15:05:59

Targeted industries: technology-and-telecommunications financial-services government-and-public-sector

Context

HtBot is a malware family known for turning infected machines into proxy servers used for generating web traffic and launching DDoS attacks. It exploits vulnerabilities to maintain control over compromised systems and is often used to anonymize attacks by redirecting traffic through victims' devices.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Htbot_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Htbot (report)

External references