Ponmocup, the full story: A giant hiding in the shadows

Ponmocup is one of the most successful and longest running botnets of the past decade. First detected in 2006, as Vundo or Virtumonde, and detected as Ponmocup starting in 2011, we believe this is one of the most underestimated botnets still under continuous development.

Though Ponmocup has received a minimal amount of attention from the security community, it is in fact a sophisticated botnet serving different purposes. Though these purposes have often been described as low-risk functionalities, the malware is actually used by a group of sophisticated criminals who use the botnet for various (financials) gains, and are likely conducting a limited amount of targeted attacks.

The whitepaper aims to provide a complete time-line and unique insight into the modus operandi of the operation around Ponmocup and describes all the important details of the malware, including as yet unknown indicators of compromise, both on host and network level, which previous research has only scratched the surface of.

Print Friendly
Maarten Van Dantzig
Threat Intelligence Analyst working at Fox-IT
Maarten Van Dantzig

Latest posts by Maarten van Dantzig (see all)

Yonathan Klijnsma
I'm a senior threat intelligence analyst working for an EU based company called Fox-IT. Both my work and hobby focus around threat intelligence in the form of malware analysis.