NgrBot
- First seen
- 2012-07-01 00:00:00
- Malware type
- botnet, credential-stealer
- Family
- Malware family
- Profile updated
- 2026-07-07 14:58:26
Context
NgrBot is a piece of malware known for forming part of a botnet and stealing user credentials. It spreads through social media platforms and removable drives, exploiting vulnerabilities to compromise systems.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Dorkbot_Ngrbot_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Dorkbot Ngrbot (report)
- Trend Micro — The Dorkbot Rises (report)
- krebsonsecurity.com — Mariposa Botnet Author Darkcode Crime Forum Admin Arrested In Germany (report)
- research.checkpoint.com — Dorkbot An Investigation (report)
- stopmalvertising.com — Analysis Of Ngrbot (report)