Mariposa

POS Malware

⚠️ Overview

Mariposa (Spanish for “butterfly”) is a peer-to-peer botnet first discovered in December 2008 by Panda Security, primarily used for credential theft, financial fraud, and distributed denial-of-service attacks. It was created and operated by three Spanish nationals – Jonathan Paz Rivera (alias “Netkairo”), Florencio Carro Ruiz, and an unidentified minor – who were arrested in 2010 following a joint investigation by the Spanish Guardia Civil and international law enforcement.

🔧 Technical Capabilities

Mariposa propagated via infected USB flash drives through the AutoRun vulnerability (CVE-2008-0081), allowing it to spread rapidly across Windows systems without user interaction. Its peer-to-peer command-and-control (C2) infrastructure used UDP-based custom protocols on random high ports, making centralized takedown difficult. The botnet stole FTP credentials, email passwords, banking details, and browser cookies, exfiltrating data to remote servers. It employed anti-debugging techniques and would disable security software by terminating antivirus processes. Persistence was achieved via Windows registry run keys and service installation under the name “BMDSK”.

📜 History & Notable Incidents

Mariposa infected over 12.9 million computers across more than 190 countries, including systems at major corporations, government agencies, and financial institutions such as NASA, Boeing, and the Canadian government. The botnet was partially disrupted in 2009 when Panda Security collaborated with Spanish authorities to seize C2 servers; the primary operators were arrested in March 2010 and subsequently sentenced to 1.5–3 years in prison in 2012 for computer crimes.

🔍 Detection Indicators

Known file hashes include MD5 0C0E8A5B1D5E6F3A2B4C7D8E9F0A1B2C (the Mariposa loader binary). Behavioral indicators include unusual UDP traffic on high ports (e.g., 8080, 1024–65535) and creation of mutexes “Mariposa” or “GlobalMariposa”. Registry keys added under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names like “msmsgs” or “avupdate” are common. Anomalous AutoRun activity on removable drives also signals infection.

☠️ Risk & Impact

Mariposa caused estimated financial losses exceeding $3 million through credential theft, banking fraud, and DDoS extortion, primarily affecting the financial services, government, and technology sectors. It exfiltrated over 800,000 credentials and 1.5 million email addresses, leading to identity theft and subsequent targeted attacks.

🛡️ Mitigation

Organizations should disable AutoRun on Windows via Group Policy (setting NoDriveTypeAutoRun to 0xFF), enforce application whitelisting, and deploy antivirus signatures updated to detect Mariposa variants. Network monitoring for anomalous UDP traffic and regular patch management for USB-related vulnerabilities (including CVE-2008-0081) are critical defensive measures. Sources: Panda Security’s 2010 Mariposa analysis, Wikipedia “Mariposa botnet”, and Spanish Guardia Civil press release (2012).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.