We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Backdoor:Win32/Codbot.AM
Detected by Microsoft Defender Antivirus
Aliases: No associated aliases
Summary
Backdoor:Win32/Codbot.AM allows attackers to control the computer through an IRC channel. The attacker can use commands to spread to other computers by scanning for network shares with weak passwords or exploiting various Windows vulnerabilities. The Trojan also allows attackers to perform other backdoor functions, such as retrieving system information from infected computers, relaying user activity, or starting and FTP server on the infected machines.