We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Win32/Codbot
Detected by Microsoft Defender Antivirus
Aliases: W32.Toxbot (Symantec) W32/Sdbot.worm.gen (McAfee) WORM_CODBOT (Trend Micro) Backdoor.Win32.Codbot (Kaspersky) W32/Codbot-Gen (Sophos) Win32.Toxbot (CA)
Summary
Windows Defender Antivirus detects and removes this threat.
Win32/Codbot is a family of network worms that targets computers running certain versions of Microsoft Windows.
Some variants of this family spread to network shares with weak administrator passwords. Other Win32/Codbot variants spread by exploiting one or more Windows vulnerabilities. The worm has a backdoor component that connects to an IRC server from an infected computer to receive commands from attackers.