NgrBot

First seen
2012-07-01 00:00:00
Malware type
botnet, credential-stealer
Family
Malware family
Profile updated
2026-07-07 14:58:26

Context

NgrBot is a piece of malware known for forming part of a botnet and stealing user credentials. It spreads through social media platforms and removable drives, exploiting vulnerabilities to compromise systems.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Dorkbot_Ngrbot_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Dorkbot Ngrbot (report)
  • Trend Micro — The Dorkbot Rises (report)
  • krebsonsecurity.com — Mariposa Botnet Author Darkcode Crime Forum Admin Arrested In Germany (report)
  • research.checkpoint.com — Dorkbot An Investigation (report)
  • stopmalvertising.com — Analysis Of Ngrbot (report)

External references