logo

dorkbot-hunting-zombies-in-latin-america.pdf

ID: ae40a2de-5ca6-4aea-a25e-9e5ceecfe36d

STIX ID: report--ae40a2de-5ca6-4aea-a25e-9e5ceecfe36d

Threat Score

75/100

Uploaded: 2026-08-05

Published Date: 2026-08-05

Last Modified Date: 2026-08-05

Created by: gogogo

TLP:GREEN
...
...
This ESET Latin America report analyzes Win32/Dorkbot (Ngrbot), an IRC-controlled worm/botnet that propagated via LNK/USB autorun and social engineering to steal credentials and spread phishing campaigns across Latin America in 2011–2012; it details variants, distribution (up to ~80,000 unique connections tracked), technical capabilities (API hooks, process injection, IRC C2, update and phishing lists), sample IOCs, and region-specific social-engineering campaigns.