EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/cyberattack/kelihos-botnet
376/430

File EL-0055HighColdCyberattack / Botnet Operation

Kelihos Botnet

Also filed as Kelihos · Kelihos Botnet

Kelihos was a significant botnet active around 2010, primarily known for its massive spam campaigns and its ability to compromise a wide array of internet-connected devices. It utilized a sophisticated command and control structure to manage infected hosts for various malicious activities. The botnet was instrumental in generating large volumes of spam and participating in DDoS attacks globally.

  • #botnet
  • #ddos
  • #malware
  • #spam
  • #botnet-command-and-control
Notoriety6/10
Event
1 Jan 2010
Disclosed
1 Jan 2010
Target
Global PCs
Actor
Kelihos Operators
Scale
Massive (estimated terabytes of spam traffic)
Status
Cold

01Summary

The Kelihos botnet emerged as a major threat in the early 2010s, targeting vulnerable systems across the globe. Its primary function was to establish a large network of compromised machines (bots) capable of executing spam campaigns and launching coordinated denial-of-service attacks. The botnet was highly effective because it often spread through exploiting weak passwords and unpatched vulnerabilities on residential and corporate networks. Researchers noted its sophisticated command and control (C2) infrastructure, which allowed operators to issue commands to thousands of bots simultaneously. The botnet's activities included credential harvesting, spam distribution, and participating in large-scale DDoS attacks, making it a significant early example of coordinated cybercrime.

02Background

The early 2010s marked a period of rapid growth in internet connectivity, which simultaneously created a larger attack surface for cybercriminals. Botnets like Kelihos capitalized on the widespread use of default or weak passwords and the slow adoption of robust network security practices. This environment allowed criminal groups to build massive, decentralized networks of compromised devices.

03Key revelations

  1. 01The sheer scale of spam generated, overwhelming global email infrastructure.
  2. 02The effectiveness of exploiting common, easily guessable passwords across diverse devices.
  3. 03The sophisticated, decentralized nature of the C2 infrastructure.

04Technical analysis

Kelihos typically operated by exploiting common vulnerabilities, often related to weak authentication or outdated services (e.g., Telnet, FTP). The malware payload was designed to establish persistence on the infected host and maintain communication with the C2 server. The botnet utilized various protocols for command reception and execution, allowing it to manage diverse types of compromised endpoints, from PCs to routers.

Attack vector
Exploitation of weak credentials, unpatched vulnerabilities, and default configurations on internet-connected devices.
Attack method
Command and Control (C2) network management, followed by coordinated spamming and DDoS attacks.
Initial access
Brute-forcing weak credentials or exploiting known service vulnerabilities.
Lateral movement
Scanning local networks for other vulnerable devices.
Persistence
Registry modifications or service installation to ensure continued operation.
Exfiltration
Sending harvested credentials and data via spam/network traffic.
Tool / malware
Kelihos Malware
Malware family
Botnet Malware
Malware type
Botnet/Spam Sender/DDoS Tool

Vulnerabilities exploited

  • Weak Passwords
  • Outdated Services

MITRE ATT&CK techniques

  • T1071.001
  • T1566.001

05Threat actor

The operators of Kelihos were highly organized criminal entities, focused purely on maximizing profit through volume. They did not target specific political or ideological goals, but rather exploited the global infrastructure for financial gain via spam and denial-of-service attacks.

MITRE groups

  • T1190

Attribution sources

  • Security Researchers

06Victims and impact

Additional victims

  • Global internet infrastructure

Countries affected

  • Global

07Data exposed

Data types

  • Credentials
  • Spam content
  • Network traffic metadata

Notable documents

  • Kelihos C2 communication logs (researcher findings)

08Financial damage

Damage was primarily measured in lost bandwidth, reputation damage, and operational costs for victims.

09Timeline

  1. 2010-01-01Initial detection and widespread activity of the Kelihos botnet.

10Reaction and fallout

Public reaction

The incident highlighted the urgent need for global password hygiene and the implementation of multi-factor authentication across all internet-connected devices. It spurred increased awareness among consumers regarding the risks of weak passwords.

Political impact

It contributed to the growing international focus on cybercrime legislation and the need for standardized security protocols for critical internet infrastructure.

11Legal

No specific major legal outcome is documented, but the incident contributed to the global push for stronger cybersecurity regulations.

12Aftermath

Policy changes

  • Increased emphasis on Multi-Factor Authentication (MFA)
  • Global best practices for password complexity and management

Regulatory changes

  • Industry guidelines for network security hardening

Security improvements

  • Deployment of advanced spam filtering and network monitoring tools
  • Mandatory password rotation policies

13Significance and legacy

Significance

Kelihos is historically significant as an early, large-scale example of a botnet that successfully leveraged weak, common credentials for massive, coordinated cybercrime. It demonstrated the economic viability of spam and DDoS attacks, setting a precedent for subsequent, more sophisticated ransomware and extortion campaigns.

Legacy

The botnet's existence accelerated the industry shift toward proactive network defense, emphasizing the importance of endpoint security, credential management, and the necessity of layered defense mechanisms against automated attacks.

14Disclosure and media

Authentication
Network traffic analysis and malware reverse engineering

Publishing organisations

  • Security Researchers

15Related files

Went on to inspire

  • Botnet evolution (e.g., Mirai, subsequent ransomware campaigns)

16Field notes

  1. 01The botnet's primary method of spreading was often through exploiting services like Telnet, which historically lacked strong authentication.
  2. 02Kelihos was one of the early indicators that cybercrime would become a highly industrialized, profit-driven sector.

17Resolution

The botnet's operational effectiveness declined over time due to increased security awareness, better network monitoring, and the development of more robust anti-spam and anti-DDoS countermeasures.

18Sources

References

  1. [1]Cybersecurity Research Reports (2010-2012)
Fact sheetEL-0055

Dates

Event
1 Jan 2010
Started
1 Jan 2010
Ended
1 Jan 2010
Discovered
1 Jan 2010
Disclosed
1 Jan 2010
Ongoing
No

Target

Organisation
Global PCs
Type
Technology Company
Sector
Internet Services
Country
Global

Actor

Name
Kelihos Operators
Type
Criminal Gang
Motivation
Financial gain through spam, credential harvesting, and Distributed Denial of Service (DDoS) attacks.
Attribution
Low
Status
Active
Arrested
No
Convicted
No

Data

Volume
Massive (estimated terabytes of spam traffic)
Sensitivity
Internal
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.