Conficker

lore

security

The 2008 Windows worm that built one of history's largest botnets and popularized domain-generation algorithms.

Exploiting the MS08-067 vulnerability from November 2008 onward, Conficker infected millions of machines at its peak and rallied an industry-wide Conficker Working Group against it, with Microsoft posting a 250,000-dollar bounty on its authors. Its daily crop of algorithmically generated rendezvous domains forced defenders to preregister thousands of names, making the DGA a standard chapter of malware analysis. Infected relics kept phoning home for years, a monument to unpatched legacy fleets.

Conficker, from late 2008, infected millions of machines and is notable for the sophistication of its coordination rather than its payload. It generated hundreds of pseudo-random domain names daily for command and control, which meant defenders had to predict and pre-register domains to interrupt it, and later variants moved to peer-to-peer communication that removed the central point entirely.

The response was equally notable. An informal coalition of researchers, registrars and vendors formed to register the generated domains ahead of the worm, which required cooperation across organizations and jurisdictions that had no formal mechanism for it. That coalition is one of the first examples of the ad hoc industry cooperation now routine in major incidents.

The unresolved part is what makes it interesting. The infrastructure was extensively built, carefully defended, and never used for anything much, so the purpose remains unclear. Millions of machines remained infected for years afterwards, in medical devices, industrial systems and machines nobody could patch, which is a reminder that infection persists long after attention moves on, and that the long tail of a worm is measured in the systems nobody can reach.

Also known as: Downadup, Kido

All glossary entries