Nitol
- First seen
- 2012-09-01 00:00:00
- Malware type
- botnet, ddos
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:38:21
- Profile updated
- 2026-07-07 14:44:30
Targeted industries: technology-and-telecommunications government-and-public-sector
Targeted regions: country_code:cn country_code:us
Context
Nitol is a type of malware identified as a botnet that is often used for distributed denial-of-service (DDoS) attacks. It typically spreads through infected devices in a large network and has been notably targeting regions such as China and the United States.
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Nitol (yara-rule)
- MALPEDIA_Win_Nitol_Auto (yara-rule)
Reports & references
- asec.ahnlab.com — 44504 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Nitol (report)
- Wikipedia — Nitol Botnet (report)
- Microsoft — Microsoft Disrupts The Emerging Nitol Botnet Being Spread Through An Unsecure Supply Chain (report)
- krebsonsecurity.com — Nitol (report)