Mariposa
Aliases: Autorun, Palevo, Rimecud
- First seen
- 2008-12-01 00:00:00
- Malware type
- botnet, worm
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:38:36
- Profile updated
- 2026-07-07 14:58:28
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Context
Mariposa, also known as Palevo, Autorun, or Rimecud, is a botnet malware family primarily used for data theft and distributed denial-of-service (DDoS) attacks. It spreads through infected USB drives and compromised websites, targeting users' financial information and sensitive data.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Mariposa_Auto (yara-rule)
Reports & references
- krebsonsecurity.com — Mariposa Botnet Author Darkcode Crime Forum Admin Arrested In Germany (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Mariposa (report)
- us-cert.gov — Icsa 10 090 01 (report)
- defintel.com — Mariposa Analysis (report)