Nitol

First seen
2012-09-01 00:00:00
Malware type
botnet, ddos
Family
Malware family
Last IoC activity
2026-07-22 00:38:21
Profile updated
2026-07-07 14:44:30

Targeted industries: technology-and-telecommunications government-and-public-sector

Targeted regions: country_code:cn country_code:us

Context

Nitol is a type of malware identified as a botnet that is often used for distributed denial-of-service (DDoS) attacks. It typically spreads through infected devices in a large network and has been notably targeting regions such as China and the United States.

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Nitol (yara-rule)
  • MALPEDIA_Win_Nitol_Auto (yara-rule)

Reports & references

  • asec.ahnlab.com — 44504 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Nitol (report)
  • Wikipedia — Nitol Botnet (report)
  • Microsoft — Microsoft Disrupts The Emerging Nitol Botnet Being Spread Through An Unsecure Supply Chain (report)
  • krebsonsecurity.com — Nitol (report)

External references