Nitol

Category: ddos_bot · Aliases: None known · Sample count (EMBER 2018): 694 · Enrichment: hand-curated · Updated: 2026-05-27

Overview

Nitol is a DDoS botnet family that uses infected machines to launch distributed denial-of-service attacks. It spreads through software supply-chain compromise and pirated software, and was notably distributed via counterfeit Windows installations sold in some regions. Microsoft disrupted the Nitol botnet in 2012 through its Operation b70 action.

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1498 T1071.001

Frequently Asked Questions

What is Nitol?

Nitol is a DDoS botnet family that uses infected machines to launch distributed denial-of-service attacks. It spreads through software supply-chain compromise and pirated software, and was notably distributed via counterfeit Windows installations sold in some regions. Microsoft disrupted the Nitol botnet in 2012 through its Operation b70 action.

How does Nitol spread?

Nitol is a DDoS-capable trojan spread through pirated Windows installations preloaded at the supply-chain level and cracked software downloads.

What are the signs of a Nitol infection?

Outbound flood traffic to unfamiliar IPs, unexpected high bandwidth usage, and antivirus detections for Nitol or Win32/Nitol are common.

What should I do if I think I have Nitol on my system?

If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Need help with an active incident? If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/nitol.json

About this catalog

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families extracted from the EMBER 2018 benchmark. The catalog is also published on Hugging Face and Kaggle.