s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.glupteba_proxy

📛 Threat Title

Malware family: Glupteba Proxy

Category: Glupteba Proxy First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.glupteba_proxy`. Printable name: Glupteba Proxy.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (9)

  • web:any.run

    Glupteba malware is a loader with information-stealing functionality. It can also relay traffic via a downloadable component. Follow live malware statistics of this dropper and get new reports, samples, IOCs, etc.

  • web:github.com

    Glupteba A sophisticated malware strain known for its stealthy behavior and multiple functionalities, including cryptocurrency mining, information stealing, and proxy tunneling.

  • web:halilozturkci.com

    The afternoon session of May 22, 2026 surfaced three distinct threats warranting immediate operator attention. First, Black Lotus Labs researchers reported a...

  • web:malwaretips.com

    The Glupteba malware botnet has sprung back into action, infecting devices worldwide after its operation was disrupted by Google almost a year ago. In December 2021, Google managed to cause a massive disruption to the blockchain-enabled botnet, securing the court orders to take control of the botnet's infrastructure and filing complaints against two Russian operators. Nozomi now reports that ...

  • web:research.openanalysis.net

    Overview Taking a look at some random GO malware with light obfuscation. Possibly linked to Glubteba. According to Sophos there are 3 possible GO components linked to a Glupteba infection.

  • web:www.bsi.bund.de

    Name of Malware : Glupteba (Carberp) Type of Malware : Click fraud, info stealer, trojan, downloader Affected Operating Systems: Windows Affected Device Types: PCs, laptops and in the second stage IoT devices (including MikroTik and Netgear) Impact: high What is Glupteba ? Glupteba is a trojan for Windows devices, it is an innocuous-looking malicious computer program. Among other things, it has ...

  • web:www.cybereason.com

    The majority of Glupteba's history has revolved around Operation Windigo, though over the years the malware has matured significantly to be part of its own botnet and distributed via Adware. The Cybereason Nocturnus team has seen recent Glupteba variants differentiate in their tactics, techniques, and procedures from what was known previously.

  • web:www.securityweek.com

    The malware has been around since 2014 and is mainly distributed through pay-per-install networks and traffic distribution systems. Google and its industry partners have taken action to disrupt command and control (C&C) infrastructure used by the Glupteba botnet.

  • web:www.vcindi.com

    Glupteba's Capabilities Glupteba is not merely a run-of-the-mill malware ; it boasts a wide array of functionalities designed to wreak havoc on infected systems. This includes information theft, backdoor access provision, cryptocurrency mining, deployment of proxy components, and leveraging the Bitcoin blockchain for command-and-control operations.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.