Glupteba Proxy

Malware

⚠️ Overview

Glupteba Proxy is a component of the Glupteba botnet, a modular malware family first identified in 2011 that primarily targets Windows systems for credential theft, cryptocurrency mining, and proxy services. It is operated by a financially motivated threat actor linked to Russian‑speaking cybercriminal forums and is classified as a botnet with stealer and proxy capabilities. The proxy module turns infected machines into SOCKS5 proxies, enabling illicit traffic relay and click fraud operations.

🔧 Technical Capabilities

Glupteba propagates via brute‑force attacks on RDP services, exploit kits, and malvertising, often using the EternalBlue exploit (CVE‑2017‑0144) for lateral movement. Its command‑and‑control (C2) infrastructure uniquely leverages the Bitcoin blockchain to store encrypted C2 server addresses, making takedowns difficult. The malware employs DLL side‑loading (MITRE T1574.002) for persistence and uses obfuscated JavaScript loaders to evade detection. It disables security software via process injection and registry modifications, and the proxy module communicates over SOCKS5 to anonymize malicious traffic. Glupteba also includes a credential stealer that harvests browser cookies and saved passwords from Chrome and Firefox, and a cryptominer that consumes CPU resources.

📜 History & Notable Incidents

Glupteba first appeared in 2011, but gained major attention in December 2021 when Google’s Threat Analysis Group (TAG) disrupted the botnet by seizing 63 domains and 2 million fraudulent Google accounts. The operation was coordinated with Chainalysis, Palo Alto Networks, and other partners. No specific high‑profile victims have been publicly named, but the botnet infected over 1 million Windows devices at its peak. While Glupteba does not exploit unique CVEs, it leverages older vulnerabilities like EternalBlue and ProxyLogon (CVE‑2021‑26855) in some campaigns, as documented in MITRE ATT&CK software entry S1072.

🔍 Detection Indicators

Indicators of compromise include known SHA256 hashes (e.g., from Google’s TAG report) and network traffic to Bitcoin‑related IPs on ports 8333 or 18333. Behavioral signatures include unusual outbound connections on non‑standard ports and execution of PowerShell scripts that decode base64‑encoded commands. Registry keys associated with persistence include HKCUSoftwareMicrosoftWindowsCurrentVersionRun entries naming random 8‑character strings. The proxy module uses User‑Agent strings mimicking legitimate browsers like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". Additional IOCs include the mutex name "GlobalGluptebaProxyMutex" observed in sandbox analyses.

☠️ Risk & Impact

Glupteba causes data exfiltration of credentials and financial information, leading to account takeover and fraud. Infected machines are used as proxies for click fraud, spam relay, and DDoS amplification, resulting in reputational damage and operational downtime. The malware’s cryptomining component significantly increases electricity costs and hardware degradation for victims across all sectors, but particularly affects small‑to‑medium enterprises with weak perimeter defenses. Financial losses from click fraud alone have been estimated in the millions of dollars annually.

🛡️ Mitigation

Defenses include applying security patches for known vulnerabilities (especially CVE‑2017‑0144 and CVE‑2021‑26855), enabling multi‑factor authentication on RDP, and deploying endpoint detection and response (EDR) solutions with behavioral analysis. Network administrators should block outbound connections to known malicious Bitcoin wallet addresses and SOCKS5 proxy traffic, while also monitoring for anomalous PowerShell execution, registry modifications, and the presence of the GluptebaProxyMutex mutex.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.