dorkbot-hunting-zombies-in-latin-america.pdf
ID: ae40a2de-5ca6-4aea-a25e-9e5ceecfe36d
STIX ID: report--ae40a2de-5ca6-4aea-a25e-9e5ceecfe36d
Threat Score
75/100
Uploaded: 2026-08-05
Published Date: 2026-08-05
Last Modified Date: 2026-08-05
Created by: gogogo
TLP:GREEN
...
...
This ESET Latin America report analyzes Win32/Dorkbot (Ngrbot), an IRC-controlled worm/botnet that propagated via LNK/USB autorun and social engineering to steal credentials and spread phishing campaigns across Latin America in 2011–2012; it details variants, distribution (up to ~80,000 unique connections tracked), technical capabilities (API hooks, process injection, IRC C2, update and phishing lists), sample IOCs, and region-specific social-engineering campaigns.
