Also known as: Kido, Downadup
Executive Summary
Conficker remains a high‑risk worm that continues to surface on older Windows systems via the MS08‑067 SMB vulnerability. It achieves persistence through registry tweaks, employs dynamic DNS for C&C communication, and can spread to removable media and network shares, posing significant threats to both corporate networks and critical infrastructure. Security teams should promptly patch vulnerable systems and monitor for outbound traffic to Conficker’s known domains.
Enhanced Description
Conficker, also known as Kido or Downadup, is a sophisticated computer worm first identified in October 2008 that exploited the MS08‑067 vulnerability in Microsoft Windows SMB services to propagate across networks. Upon infection, Conficker installs a payload that modifies critical system processes and registry keys to maintain persistence. The malware establishes command-and-control (C&C) infrastructure through a combination of domain name generation algorithms and hard‑coded fallback servers, enabling remote actors to issue commands over HTTP/HTTPS and to download additional modules. It actively scans for removable media and other infected hosts, using SMB, Windows Management Instrumentation, and various system discovery techniques to expand its footprint. The worm’s impact has been historically significant; beyond the widespread denial‑of‑service effect on corporate networks in 2008–2011, a 2016 variant reportedly infiltrated critical systems at a nuclear power plant via removable drives. This incident underscored Conficker’s adaptability and potential for targeting mission‑critical infrastructure. Modern indicators show that while original variants are largely dormant, newer descendants continue to surface on legacy Windows installations, exploiting unpatched SMB flaws and leveraging DNS-based domain generation to evade detection.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The information is drawn from well‑documented public reports and technical analyses of the original Conficker releases, providing high confidence in general capabilities. However, data on the latest variants circulating in 2024 are limited; gaps exist regarding new persistence methods or command‑and‑control evolution that may not be fully captured here.
Conficker is a computer worm first detected in October 2008 that targeted Microsoft Windows using the MS08-067 Windows vulnerability to spread.(Citation: SANS Conficker) In 2016, a variant of Conficker made its way on computers and removable disk drives belonging to a nuclear power plant.(Citation: Conficker Nuclear Power Plant)