Kelihos

Malware

⚠️ Overview

Kelihos (also known as Hlux) is a modular botnet first discovered in December 2010 by security researchers at Kaspersky, primarily used for spam distribution, credential theft, and as a proxy network. It is believed to be operated by a Russian-speaking threat actor group tracked as TA544, with its code derived from the earlier Waledac botnet. Kelihos is classified as a botnet and information stealer, leveraging a peer-to-peer (P2P) command-and-control (C2) infrastructure to resist takedown efforts.

🔧 Technical Capabilities

Kelihos propagates via malicious email attachments (often disguised as shipping notifications or invoices) and exploits weak credentials through brute-force attacks on Remote Desktop Protocol (RDP) and SSH services. The malware uses a custom P2P protocol to communicate with other infected nodes, with each node serving as both client and server; this makes it highly resilient to C2 disruption. For persistence, Kelihos creates a scheduled task or registry run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunKelihos) and installs a kernel-mode rootkit component to hide its processes. Evasion techniques include packing its executable with multiple layers (UPX, custom packers), checking for sandbox environments by detecting VMware or VirtualBox processes, and disabling Windows Defender through WMI commands. The malware can harvest stored credentials from browsers (Chrome, Firefox, Internet Explorer), FTP clients, and email clients (Outlook), and it can also perform man-in-the-middle attacks on HTTP traffic to inject spam payloads.

📜 History & Notable Incidents

Kelihos first emerged in 2010 as a successor to the Waledac botnet, which had been disrupted by Microsoft in February 2010. In September 2011, Microsoft, together with the FBI and Kaspersky, executed a coordinated takedown of the Kelihos botnet by seizing 800 domain names and court-ordered P2P sinkholes, but the botnet was rebuilt within days. A second takedown occurred in March 2017 when Microsoft and the US District Court for the Eastern District of Virginia obtained a default judgment against the botnet's operator, Andrey N. S., a Russian national; the operation resulted in the seizure of 88 domains and the sinkholing of the Kelihos P2P network. No specific CVEs are directly tied to Kelihos, but it exploited weak RDP credentials (CVE-2016-0125 unrelated, but commonly abused).

🔍 Detection Indicators

Known file hashes include the SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (example from a 2017 sample) but actual IOCs are domain-specific; behavioral signatures include outbound connections on TCP ports 80, 443, and 8080 to randomized subdomains of known malicious domains (e.g., *.kelihos.net), registry key creation at HKCUSoftwareMicrosoftWindowsCurrentVersionRunsvchost, and a mutex name such as GlobalKelihos. Network IOCs include User-Agent strings like Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 used for HTTP beaconing, and DNS queries to domains hosted on bulletproof providers in Eastern Europe.

☠️ Risk & Impact

Kelihos primarily causes data exfiltration of stored credentials and email addresses, leading to account takeover and further spam campaigns; it has been implicated in distributing banking trojans (e.g., Zeus) and ransomware (e.g., Locky) via its spam relays. Financial losses are difficult to quantify but the 2017 takedown affected over 100,000 infected systems worldwide, with significant impact on the hospitality, education, and healthcare sectors in the United States and Europe. The botnet's proxy functionality also enables attackers to anonymize other criminal activities, amplifying its harm.

🛡️ Mitigation

Defenders should enforce strong password policies for RDP and SSH accounts, apply multi-factor authentication, and deploy network segmentation to limit lateral movement. Detection rules include Suricata signatures for Kelihos P2P traffic patterns and YARA rules for the malware's unique XOR encryption keys, as documented in MITRE ATT&CK technique T1083 (File and Directory Discovery) and T1071.001 (Application Layer Protocol: Web Protocols). Regular patching of known vulnerabilities and use of endpoint detection and response (EDR) tools like Microsoft Defender for Endpoint with its Kelihos-specific behavioral detection can mitigate infection.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.