Mariposa

Aliases: Autorun, Palevo, Rimecud

First seen
2008-12-01 00:00:00
Malware type
botnet, worm
Family
Malware family
Last IoC activity
2026-07-22 00:38:36
Profile updated
2026-07-07 14:58:28

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Context

Mariposa, also known as Palevo, Autorun, or Rimecud, is a botnet malware family primarily used for data theft and distributed denial-of-service (DDoS) attacks. It spreads through infected USB drives and compromised websites, targeting users' financial information and sensitive data.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Mariposa_Auto (yara-rule)

Reports & references

  • krebsonsecurity.com — Mariposa Botnet Author Darkcode Crime Forum Admin Arrested In Germany (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Mariposa (report)
  • us-cert.gov — Icsa 10 090 01 (report)
  • defintel.com — Mariposa Analysis (report)

External references