OnlinerSpambot is a credential-stealing botnet and spam malware first documented in 2016 by security researchers at RiskIQ (now Microsoft) and later detailed by Trend Micro. It is categorized as a spambot and credential harvester, primarily operated by a Russian-speaking cybercriminal group known as "Onliner." The malware is designed to exfiltrate stolen credentials from infected hosts and propagate spam campaigns using compromised email accounts.
OnlinerSpambot spreads via malicious email attachments and exploit kits, with initial infection often leveraging the RIG exploit kit targeting vulnerabilities in Internet Explorer and Flash (e.g., CVE-2018-8174). Once installed, it establishes persistence via a scheduled task or registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. The botnet uses a modular architecture with a main binary that downloads additional modules, including a socks5 proxy for relaying spam traffic and a credential stealer that harvests saved credentials from web browsers, FTP clients, and email clients. Command-and-control (C2) communication is encrypted over HTTP/HTTPS, with the malware contacting hardcoded domains or IP addresses and using a custom XOR-based encoding. Evasion techniques include anti-debugging checks, process hollowing, and checking for sandbox environments. The malware also disables Windows Defender and updates itself via a remote configuration file.
First identified in 2016, OnlinerSpambot gained notoriety in 2018 when RiskIQ reported that the botnet had compromised over 711 million email addresses and 2.2 million passwords. In 2019, Trend Micro linked OnlinerSpambot to a large-scale credential-stealing campaign targeting online retail and banking platforms. No specific law enforcement takedown has been publicly recorded, but the botnet’s activity declined after Microsoft’s disruption of the RIG exploit kit infrastructure in 2020. The malware has exploited vulnerabilities such as CVE-2018-8174 (VBScript Engine Remote Code Execution) and CVE-2018-15982 (Flash Player Use-After-Free).
Indicators of compromise include specific file hashes such as SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample) and registry persistence under HCUSoftwareMicrosoftWindowsCurrentVersionRun with key names like "WindowsUpdate." Network IOCs include outbound HTTPS connections to domains under .xyz and .top TLDs, User-Agent strings mimicking "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko," and mutex names such as "GlobalOnlinerSpambotMutex." Behavioral signatures include high volumes of outbound SMTP traffic and modification of browser credential stores.
OnlinerSpambot primarily causes data exfiltration of login credentials, which are sold on underground forums or used for account takeover, leading to financial losses for individuals and businesses. The botnet’s spam modules also facilitate phishing campaigns and malware distribution, impacting sectors such as e-commerce, banking, and email services. RiskIQ estimated that the botnet had accessed over 2.5 billion unique credentials by 2018.
To mitigate OnlinerSpambot, organizations should apply patches for CVE-2018-8174 and CVE-2018-15982, enable multi-factor authentication, and deploy email filtering to block malicious attachments. Endpoint detection and response (EDR) solutions with behavioral monitoring for credential stealing and unauthorized SMTP traffic are recommended, along with network IOCs from MITRE ATT&CK technique T1114 (Email Collection) and T1056 (Input Capture).
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.