Lethic

Category: spam_bot · Aliases: None known · Sample count (EMBER 2018): 4,879 · Enrichment: hand-curated · Updated: 2026-05-27

Overview

Lethic is a long-running spambot family active since 2008 that turns infected machines into spam-relay nodes for pharmaceutical, phishing, and malware-distribution campaigns. Lethic uses its own custom protocol to communicate with command-and-control servers and is notable for its compact size and resilience. Its primary harm to victims is bandwidth consumption and potential blacklisting of the victim's IP address.

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1071.001

Frequently Asked Questions

What is Lethic?

Lethic is a long-running spambot family active since 2008 that turns infected machines into spam-relay nodes for pharmaceutical, phishing, and malware-distribution campaigns. Lethic uses its own custom protocol to communicate with command-and-control servers and is notable for its compact size and resilience. Its primary harm to victims is bandwidth consumption and potential blacklisting of the victim's IP address.

How does Lethic spread?

Lethic is a spam-bot trojan that infects systems through other malware droppers and uses them as nodes for sending pharmaceutical and stock spam.

What are the signs of a Lethic infection?

Sudden spike in outbound SMTP traffic, IP address appearing on email blocklists, and antivirus detections for Lethic or Spam-Bot.Lethic indicate participation in the botnet.

What should I do if I think I have Lethic on my system?

If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Need help with an active incident? If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/lethic.json

About this catalog

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families extracted from the EMBER 2018 benchmark. The catalog is also published on Hugging Face and Kaggle.