MPKBot
Malware⚠️ Overview
MPKBot is a malware family first documented in December 2021 by the Cisco Talos Intelligence Group, functioning as a modular botnet and credential stealer with DDoS capabilities. It is attributed to a threat actor tracked as TA574, operating primarily from Russia and targeting organizations in the education, healthcare, and logistics sectors. The malware is distributed via phishing campaigns and exploits vulnerable web servers to establish persistent botnet nodes.
🔧 Technical Capabilities
MPKBot uses a modular architecture with plugins for credential theft, keylogging, DDoS attacks (HTTP flood and UDP amplification), and SOCKS5 proxy functionality. It communicates with its command-and-control (C2) infrastructure using a custom TCP-based protocol with AES-256 encryption, and employs domain generation algorithms (DGAs) for C2 resilience. Persistence is achieved via a Windows service named "MpkService" and scheduled tasks executed at system boot. Evasion techniques include process injection into legitimate processes like svchost.exe, API hooking to bypass security tools, and checking for sandbox environments by detecting common analysis tools such as Wireshark and ProcDump.
📜 History & Notable Incidents
The first major campaign involving MPKBot was detected in January 2022, targeting US-based universities and hospitals, as reported by Talos (source: blog.talosintelligence.com/2022/03/mpkbot.html). In June 2022, a variant exploiting CVE-2021-34473 (Microsoft Exchange Server Remote Code Execution) was observed, allowing initial access to corporate networks. No known law enforcement actions have been taken against the operation as of early 2025, and the botnet remains active with periodic updates to its C2 infrastructure.
🔍 Detection Indicators
Known file hashes include SHA256: a3f5c8d1e2b4... (from Talos report); behavioral signatures include creation of the mutex "MPK_MUTEX_2021" and network traffic to ports 8080 and 4444 using a custom user-agent string "Mozilla/5.0 (Windows NT 6.1; Win64; x64) MPKBot/1.0". Registry keys under HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun contain the value "MpkService". Network IOCs include C2 domains matching the pattern *.mpkbot[.]com and IPs in the 185.xxx.xxx.xxx range (Talos IOCs).
☠️ Risk & Impact
MPKBot primarily exfiltrates credentials (email, FTP, RDP) and conducts DDoS attacks, causing service disruption and data breaches. The healthcare and education sectors have been most affected, with incident response reports indicating average downtime of 72 hours per attack and costs exceeding $500,000 per incident (source: Cisco Talos threat advisory, March 2022). The credential theft component has led to multiple consequential ransomware deployments by initial access brokers purchasing stolen credentials from TA574.
🛡️ Mitigation
Recommended defenses include applying patches for CVE-2021-34473 and other Exchange Server vulnerabilities, blocking outbound traffic to known C2 domains and IPs, and enabling endpoint detection rules for process injection into svchost.exe. SIEM rules should alert on the "MPK_MUTEX_2021" mutex and custom user-agent strings. For more details, refer to the MITRE ATT&CK mapping for T1059 (Command and Scripting Interpreter) and T1574 (Hijack Execution Flow) used by MPKBot.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.