{
  "family": "conficker",
  "sample_count": 11,
  "category": "worm",
  "description": "Conficker is a computer worm first detected in October 2008 that, per MITRE ATT&CK, targeted Microsoft Windows using the MS08-067 vulnerability to spread. It infected millions of machines worldwide, spread via removable drives and weak network shares, and disabled security updates and tools. In 2016 a variant reportedly reached computers and removable drives at a nuclear power plant, illustrating its persistence.",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Conficker",
    "Downadup",
    "Kido"
  ],
  "enrichment_level": "curated_sourced",
  "faq": [
    {
      "@type": "Question",
      "name": "What is Conficker?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "A computer worm first detected in October 2008 that spread using the Windows MS08-067 vulnerability and infected millions of machines."
      }
    },
    {
      "@type": "Question",
      "name": "How did Conficker spread?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Through the MS08-067 Windows vulnerability, removable USB drives, and weakly protected network shares."
      }
    },
    {
      "@type": "Question",
      "name": "Why was Conficker hard to eradicate?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It disabled security services and updates, spread through multiple methods, and used domain-generation to locate command servers."
      }
    },
    {
      "@type": "Question",
      "name": "Is Conficker still around?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Yes; MITRE notes a variant reached systems at a nuclear power plant as late as 2016, showing how long it persisted on unpatched machines."
      }
    },
    {
      "@type": "Question",
      "name": "How is Conficker prevented?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Applying the MS08-067 patch and disabling autorun on removable media addressed its main infection routes."
      }
    },
    {
      "@type": "Question",
      "name": "What are Conficker's other names?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It is also known as Downadup and Kido."
      }
    },
    {
      "@type": "Question",
      "name": "Where is the authoritative reference?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "MITRE ATT&CK's Conficker entry (S0608), linked on this page."
      }
    }
  ],
  "faq_count": 7,
  "mitre_attack": [
    "T1210",
    "T1547.001",
    "T1547.010",
    "T1571"
  ],
  "cisa_advisory": "https://www.cisa.gov/news-events/alerts/2009/03/29/conficker-p2p-worm",
  "last_updated": "2026-06-09",
  "sources": [
    {
      "name": "MITRE ATT&CK: Conficker (S0608)",
      "url": "https://attack.mitre.org/software/S0608"
    }
  ],
  "mitre_url": "https://attack.mitre.org/software/S0608",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}