Netskope Threat Labs

Conficker

ATP Sandbox Adv. HeuristicsAV

Conficker is a computer worm first detected in October 2008 that spread by exploiting the MS08-067 vulnerability in Windows. A variant reached computers and removable disk drives at a nuclear power plant in 2016, which shows how long neglected infections can persist on critical networks.

First seen
May 2022
Last seen
October 2026
DownadupKido

13 techniques across 7 tactics.

TA0003 Persistence

  • T1543Create or Modify System Process
  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

  • T1027Obfuscated Files or Information

TA0007 Discovery

  • T1046Network Service Discovery
  • T1124System Time Discovery

TA0008 Lateral Movement

  • T1021Remote Services
  • T1091Replication Through Removable Media
  • T1210Exploitation of Remote Services

TA0011 Command and Control

TA0040 Impact

  • T1490Inhibit System Recovery

TA0112 Defense Impairment

Alert Name
Win32.Worm.Conficker
Win32.Worm.Downadup
Win32.Worm.Downadup.Gen
Win32.Worm.Downadup.H
Win32.Worm.Kido