Kelihos

First seen
2009-01-01 00:00:00
Malware type
botnet, credential-stealer, ddos
Family
Malware family
Last IoC activity
2026-07-21 18:05:41
Profile updated
2026-07-07 12:56:26

Context

Kelihos is a botnet known for sending spam emails, stealing sensitive information, and participating in distributed denial-of-service (DDoS) attacks. The botnet is capable of rapidly adapting and has been a notable presence in the cyber threat landscape. It has evolved through multiple iterations, showing resilience against takedown efforts.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Kelihos_Auto (yara-rule)

Related threat objects

  • Kelihos (infrastructure)

Reports & references

  • CrowdStrike — Farewell To Kelihos And Zombie Spider (report)
  • CrowdStrike — Inside The Takedown Of Zombie Spider And The Kelihos Botnet (report)
  • shadowserver.org — Has The Sun Set On The Necurs Botnet (report)
  • lokalhost.pl — Peering.Into.Spam.Botnets.Virusbulletin2017 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Kelihos (report)
  • cyberscoop.com — Doj Kelihos Botnet Peter Levashov Severa (report)
  • wired.com — Fbi Took Russias Spam King Massive Botnet (report)
  • justice.gov — Russian National Convicted Charges Relating Kelihos Botnet (report)
  • bleepingcomputer.com — Us Convicts Russian National Behind Kelihos Botnet Crypting Service (report)
  • Wikipedia — Kelihos Botnet (report)

External references