CACrown ArchivesThe cinema collection
Menu
Research dossier · General Reference

Dorkbot (malware)

family of malware worms that spreads through instant messaging

Cross-disciplinary reference desk with index cards, atlas, dictionary and catalogue
General referenceInterpretive dossier study · Crown Archives visual atlas
Record originEnglish Wikipedia
Text licenseCC BY-SA 4.0
Source revisionNov 9, 2025
Entity authorityQ22907913
Source-derived summary

Dorkbot is a family of malware worms that spreads through instant messaging, USB drives, websites or social media channels like Facebook. Code Shikara is a computer worm, related to the Dorkbot family, that attacks through social engineering. Particularly prevalent in 2015, Dorkbot-infected systems were variously used to send spam, participate in DDoS attacks, or harvest users' credentials.

Functionality

Dorkbot’s backdoor functionality allows a remote attacker to exploit infected systems. According to an analysis by Microsoft and Check Point Research, a remote attacker may be able to:

Download and run a file from a specified URL;

Collect login information and passwords through form grabbing, FTP, POP3, or Internet Explorer and Firefox cached login details; or

Block or redirect certain domains and websites (e.g., security sites).

Impact

A system infected with Dorkbot may be used to send spam, participate in DDoS attacks, or harvest users' credentials for online services, including banking services.

Prevalence

Between May and December 2015, the Microsoft Malware Protection Center detected Dorkbot on an average of 100,000 infected machines each month.

Remediation

In 2015, the U.S. Department of Homeland Security advised the following action to remediate Dorkbot infections:

Use and maintain anti-virus software

Change your passwords

Keep your operating system and application software up-to-date

Use anti-malware tools

Disable AutoRun

History

In 2011, Code Shikara was first identified by the Danish cyber security company CSIS. The AV-company Sophos reported in November 2011 that this threat mainly spreads itself through malicious links through the social network Facebook.

In 2013, Bitdefender Labs caught and blocked the worm, which is capable of spying on users' browsing activities, meanwhile stealing their personal online/offline information and/or credentials, commonly known as cybercrime. The infection was originally flagged by the online backup service MediaFire, who detected that the worm was being distributed camouflaged as an image file.

Editorial summary

“Dorkbot (malware)” enters the record as family of malware worms that spreads through instant messaging. Crown Archives preserves that source wording while asking what Dorkbot, malware and family can confirm, complicate or overturn.

Editorial reviewA practical starting point whose main value is the path it opens into stronger specialist and primary sources. The current lead gives the account dated anchors—2015, 2011, 2013—that can be checked directly. The selected authority fields contribute no independent date. Its strongest next move is a source search built around Dorkbot, malware and family.
Editorial analysis

Why this record matters

“Dorkbot (malware)” is worth following because a concise public description often conceals a longer documentary argument. Here, Dorkbot, malware and family provides the most credible route into that argument.

Evidence profile

Vocabulary and entity names are the principal evidence signals here, because they determine the precision of every later search. The source revision retrieved here is dated Nov 9, 2025. The linked authority identifier is Q22907913. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2015, 2011 and 2013.

Critical limits

A concise general-reference account can conceal disagreements about scope, terminology or the weight assigned to individual sources. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.

How to read it

Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.

Best used for
  • Subject orientation
  • Search vocabulary
  • Locating named sources
Verify next

The closest primary source, responsible institution and strongest cited specialist reference.

Three-step research path

  1. Establish the record: confirm the title “Dorkbot (malware)”, its source revision and the description used here.
  2. Expand the search: follow Dorkbot (malware) primary sources, Dorkbot (malware) archive and Dorkbot research across catalogues and specialist indexes.
  3. Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.

Questions for further research

  1. Which source most directly establishes the central claim about “Dorkbot (malware)”?
  2. What terminology or title could unlock a more precise catalogue search?
  3. Which institution is responsible for the underlying evidence?
Subject index

Search terms from this dossier

Source & attribution

This entry incorporates text from Dorkbot (malware)” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.