Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareExploits 2 CVEs

Dogkild

Dogkild is a Windows worm observed being downloaded and executed as a secondary payload by exploitation of Microsoft Windows Video ActiveX Control vulnerability CVE-2008-0015 (detected as Exploit:JS/CVE-2008-0015) delivered via a specially crafted web page. Microsoft reports that the exploit may connect to a remote server to download additional malware and that it has been used in the wild to deliver Dogkild. Dogkild propagates via removable drives and has capabilities including retrieving and executing additional binaries/files, overwriting certain system files, terminating a long list of security-related processes, and replacing the Windows Hosts file to block access to websites associated with security programs. No specific threat actor attribution, targeted industries, or concrete IOCs are provided in the available content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

2 CVES
CVE-2008-0015Microsoft Video ActiveX Control Remote Code Execution VulnerabilityExploited in the wild

CVE-2008-0015 (CVSS score: 8.8) - A stack-based buffer overflow vulnerability in Microsoft Windows Video ActiveX Control... Microsoft notes... it may connect to a remote server and download other malware... used to download and execute Dogkild, a worm...

via the hacker newsthehackernews.com
CVE-2020-7796SSRF in Zimbra Collaboration Suite WebEx Zimlet (zimlet JSP enabled)

Microsoft warned that the older flaw can download malware such as the Dogkild worm, which can run additional files, alter the Windows Hosts file, and disable security processes.

via scworldscworld.com
MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1091Replication Through Removable MediaEvidence1

"... Dogkild, a worm that propagates via removable drives."

T1189Drive-by CompromiseEvidence1

"CVE-2008-0015 ... A stack-based buffer overflow ... that could allow an attacker to achieve remote code execution by setting up a specially crafted web page."

Execution

1 technique
T1203Exploitation for Client ExecutionEvidence1

"CVE-2008-0015 ... A stack-based buffer overflow vulnerability in Microsoft Windows Video ActiveX Control ... by setting up a specially crafted web page."

Lateral Movement

1 technique
T1091Replication Through Removable MediaEvidence1

"... Dogkild, a worm that propagates via removable drives."

Command and Control

2 techniques
T1092Communication Through Removable MediaEvidence1

"Dogkild, a worm that propagates via removable drives."

T1105Ingress Tool TransferEvidence1

"it may connect to a remote server and download other malware"

Impact

2 techniques
T1489Service StopEvidence1

"terminate a long list of security-related processes"

T1565.001Stored Data ManipulationEvidence1

"... replace the Windows Hosts file in an attempt to prevent users from accessing websites associated with security programs."

Other

1 technique
T1562.001Disable or Modify ToolsEvidence1

"terminate a long list of security-related processes"

ACTIVITY FEED

Recent activity

6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities2

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.