Skip to main content

Boteraser | Website and Server Security Solutions

OnlinerSpambot

Malware

⚠️ Overview

OnlinerSpambot is a credential-stealing botnet and spam malware first documented in 2016 by security researchers at RiskIQ (now Microsoft) and later detailed by Trend Micro. It is categorized as a spambot and credential harvester, primarily operated by a Russian-speaking cybercriminal group known as "Onliner." The malware is designed to exfiltrate stolen credentials from infected hosts and propagate spam campaigns using compromised email accounts.

🔧 Technical Capabilities

OnlinerSpambot spreads via malicious email attachments and exploit kits, with initial infection often leveraging the RIG exploit kit targeting vulnerabilities in Internet Explorer and Flash (e.g., CVE-2018-8174). Once installed, it establishes persistence via a scheduled task or registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. The botnet uses a modular architecture with a main binary that downloads additional modules, including a socks5 proxy for relaying spam traffic and a credential stealer that harvests saved credentials from web browsers, FTP clients, and email clients. Command-and-control (C2) communication is encrypted over HTTP/HTTPS, with the malware contacting hardcoded domains or IP addresses and using a custom XOR-based encoding. Evasion techniques include anti-debugging checks, process hollowing, and checking for sandbox environments. The malware also disables Windows Defender and updates itself via a remote configuration file.

📜 History & Notable Incidents

First identified in 2016, OnlinerSpambot gained notoriety in 2018 when RiskIQ reported that the botnet had compromised over 711 million email addresses and 2.2 million passwords. In 2019, Trend Micro linked OnlinerSpambot to a large-scale credential-stealing campaign targeting online retail and banking platforms. No specific law enforcement takedown has been publicly recorded, but the botnet’s activity declined after Microsoft’s disruption of the RIG exploit kit infrastructure in 2020. The malware has exploited vulnerabilities such as CVE-2018-8174 (VBScript Engine Remote Code Execution) and CVE-2018-15982 (Flash Player Use-After-Free).

🔍 Detection Indicators

Indicators of compromise include specific file hashes such as SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample) and registry persistence under HCUSoftwareMicrosoftWindowsCurrentVersionRun with key names like "WindowsUpdate." Network IOCs include outbound HTTPS connections to domains under .xyz and .top TLDs, User-Agent strings mimicking "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko," and mutex names such as "GlobalOnlinerSpambotMutex." Behavioral signatures include high volumes of outbound SMTP traffic and modification of browser credential stores.

☠️ Risk & Impact

OnlinerSpambot primarily causes data exfiltration of login credentials, which are sold on underground forums or used for account takeover, leading to financial losses for individuals and businesses. The botnet’s spam modules also facilitate phishing campaigns and malware distribution, impacting sectors such as e-commerce, banking, and email services. RiskIQ estimated that the botnet had accessed over 2.5 billion unique credentials by 2018.

🛡️ Mitigation

To mitigate OnlinerSpambot, organizations should apply patches for CVE-2018-8174 and CVE-2018-15982, enable multi-factor authentication, and deploy email filtering to block malicious attachments. Endpoint detection and response (EDR) solutions with behavioral monitoring for credential stealing and unauthorized SMTP traffic are recommended, along with network IOCs from MITRE ATT&CK technique T1114 (Email Collection) and T1056 (Input Capture).

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.