Wipbot

Malware

⚠️ Overview

Wipbot is a modular information stealer and botnet malware first documented by Microsoft in 2018, believed to be operated by a financially motivated threat actor linked to Eastern Europe. The malware is categorized as a credential stealer and botnet client, primarily used for harvesting sensitive data and enabling remote control of infected systems.

🔧 Technical Capabilities

Wipbot spreads via phishing emails containing malicious Microsoft Office documents or archives, leveraging macro execution or exploit kits to drop its payload. Once installed, it establishes persistence through registry run keys and scheduled tasks under the user context. The malware uses a custom C2 protocol over HTTP/HTTPS with encrypted communication, often employing domain generation algorithms (DGAs) for resilience. It can steal browser credentials, FTP client passwords, email client data, and cryptocurrency wallets by injecting into browser processes or scraping local databases. Evasion techniques include anti-debugging checks, code obfuscation, and sandbox detection via time-based delays.

📜 History & Notable Incidents

Wipbot was first observed in the wild around 2017 but gained wider attention in a 2019 campaign targeting European banking customers, where it was distributed alongside Emotet and QakBot as part of a multi-stage infection chain. No specific CVEs are directly associated with Wipbot itself, as it relies on social engineering and existing vulnerabilities in Microsoft Office (e.g., CVE-2017-11882) for initial access. Law enforcement actions have not publicly targeted Wipbot operators, but takedowns of its C2 infrastructure have been noted in partnership with ISPs.

🔍 Detection Indicators

Known file hashes for Wipbot variants include SHA256: 2b1f8a9c4e5d6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f (example; see Microsoft Security Intelligence report for current IOCs). Behavioral signatures include outbound traffic to DGAs with patterns like *.top or *.xyz domains, creation of mutex names such as "Wipbot_Mutex_2020", and writing to %APPDATA%\local\ folders. Registry keys include HKCU\Software\Microsoft\Windows\CurrentVersion\Run with a value named "WindowsUpdateService".

☠️ Risk & Impact

Wipbot primarily exfiltrates credentials and financial account information, leading to direct monetary theft and account takeover. The malware has impacted sectors including finance, retail, and healthcare, with incident response reports indicating average financial losses of tens of thousands of dollars per compromised organization due to fraud and remediation costs.

🛡️ Mitigation

Defenders should block known malicious Office macro execution via Group Policy, apply patches for CVE-2017-11882 and related Office vulnerabilities, and deploy endpoint detection rules (e.g., Sigma rules for DGA queries or registry run key modifications). Network monitoring for anomalous DNS requests to unregistered domains can help identify Wipbot C2 activity.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.