Netskope Threat Labs

Doboc

ATP Sandbox Adv. HeuristicsAV

Doboc is a trojan that spreads through removable drives and provides backdoor access to infected Windows systems. It copies itself to attached storage devices so that it hops to new machines when users move media between systems, and it can download additional payloads from remote servers. Environments without restrictions on removable media are the most exposed to this style of worm like propagation.

First seen
January 2022
Last seen
October 2026
Alert Name
Trojan.Doboc.A.Dam
Trojan.Injector.Doboc.C
Trojan.Injector.Doboc.E
Trojan.Ransom.Doboc.A
Win32.Doboc.Gen.1
Win32.Doboc.Gen.2.Dam
Win64.Trojan.Doboc