Kelihos
- First seen
- 2009-01-01 00:00:00
- Malware type
- botnet, credential-stealer, ddos
- Family
- Malware family
- Last IoC activity
- 2026-07-21 18:05:41
- Profile updated
- 2026-07-07 12:56:26
Context
Kelihos is a botnet known for sending spam emails, stealing sensitive information, and participating in distributed denial-of-service (DDoS) attacks. The botnet is capable of rapidly adapting and has been a notable presence in the cyber threat landscape. It has evolved through multiple iterations, showing resilience against takedown efforts.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Kelihos_Auto (yara-rule)
Related threat objects
- Kelihos (infrastructure)
Reports & references
- CrowdStrike — Farewell To Kelihos And Zombie Spider (report)
- CrowdStrike — Inside The Takedown Of Zombie Spider And The Kelihos Botnet (report)
- shadowserver.org — Has The Sun Set On The Necurs Botnet (report)
- lokalhost.pl — Peering.Into.Spam.Botnets.Virusbulletin2017 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Kelihos (report)
- cyberscoop.com — Doj Kelihos Botnet Peter Levashov Severa (report)
- wired.com — Fbi Took Russias Spam King Massive Botnet (report)
- justice.gov — Russian National Convicted Charges Relating Kelihos Botnet (report)
- bleepingcomputer.com — Us Convicts Russian National Behind Kelihos Botnet Crypting Service (report)
- Wikipedia — Kelihos Botnet (report)