In October 2008, a worm began spreading across the internet by exploiting a vulnerability in the Windows Server service. Within weeks it had infected millions of computers. By early 2009, Conficker - also known as Downadup or Kido - had compromised an estimated 9 to 15 million machines, making it the largest botnet ever assembled at the time. Then, for years, it did almost nothing. No spam. No DDoS. No credential theft at scale. A vast army of infected computers that simply sat, waited, and updated itself while the security industry watched in bewilderment.
The Initial Exploit
Microsoft had patched the vulnerability Conficker exploited - CVE-2008-4250, a buffer overflow in the Windows Server service's NetAPI32.dll - just three weeks before the worm began spreading. The patch was MS08-067, and Microsoft had issued it as an emergency out-of-band patch, an unusual step reserved for critical vulnerabilities under active exploitation. Conficker's authors had either been working with knowledge of the vulnerability before the patch, or moved with extraordinary speed after patch release.
The vulnerability allowed remote code execution without authentication on any unpatched Windows system - XP, Vista, Server 2003, Server 2008. The worm exploited it over port 445 (SMB) and spread through network shares. It also spread via AutoRun from infected USB drives, and by brute-forcing weak administrator passwords on Windows network shares. Each infected machine immediately began scanning and attacking other machines.
The Conficker Working Group
The security industry's response to Conficker was unprecedented. ICANN, Neustar, the Internet Corporation for Assigned Names and Numbers, numerous national CERTs, and major security companies formed the Conficker Working Group in February 2009 - a formal coalition specifically to combat one piece of malware. The group pre-registered or sinkholed Conficker's DGA domains days in advance, preventing the botnet from receiving new instructions.
This was the first time the domain industry had been organized to preemptively block a specific threat at the infrastructure level. Every day, Conficker's authors had to register new domains from their algorithmically-generated list before defenders could sinkhole them. The working group developed tools to calculate the daily domain list and coordinate preemptive registration across multiple registrars in multiple country-code domains. It was a cryptographic arms race conducted through DNS administration.
Microsoft offered a $250,000 reward for information leading to the arrest of Conficker's authors. The reward was never claimed. Despite attribution attempts, the authors were never publicly identified - only circumstantial indicators pointed toward Ukraine, based on the worm's code including logic to abort infection on machines with Ukrainian keyboard layouts, and to avoid infecting Ukrainian IP address ranges.
Conficker.C and the April 1 Non-Event
In March 2009, Conficker updated itself to a new variant - Conficker.C - which contained a peer-to-peer update mechanism that allowed infected machines to share updates with each other without contacting any central server. This made the working group's domain sinkholing less effective: even if all C2 domains were blocked, Conficker could receive updates via encrypted P2P communication between infected nodes.
Conficker.C also contained code that would change its behavior starting April 1, 2009. The security community, press, and general public worked themselves into a significant panic in the weeks before April 1. Headlines predicted catastrophe. Banks and governments issued warnings. Some organizations took their machines offline preemptively.
April 1, 2009 passed without incident. The behavior change was that Conficker.C increased its polling frequency for DGA domains from 250 to 50,000 per day - a change to its own update mechanism, not an activation of any payload. There was no cyberattack. No systems were wiped. The botnet simply became better at receiving updates.
The Payload That Never Came
Conficker eventually did activate - in a limited way. In May 2009, infected machines began downloading a spam-sending component and a fake antivirus program called Waledac. The spam operation and scareware were small-scale compared to the botnet's size and represented a fraction of its potential. Researchers who had been watching the botnet expected something far more destructive from a network of millions of machines.
The mystery of Conficker's purpose was never definitively resolved. One theory: the botnet was built for sale or lease, and the April 1 media attention made it too risky to deploy at full scale. The massive public awareness campaign - including the Microsoft reward and working group - meant that any significant malicious action would face immediate scrutiny and response. The authors may have decided the botnet was too hot to monetize.
Another theory: Conficker was a test or proof-of-concept, built to demonstrate capabilities to potential buyers in the criminal underground rather than to directly operate. The sophisticated DGA, peer-to-peer updates, and infection mechanisms were more advanced than most botnets of the era. A demonstration of that infrastructure had value independent of any specific payload.
Legacy
Conficker infections persisted for over a decade. The worm spread to hospital networks, manufacturing equipment, and other industrial systems running unpatched Windows XP long after Microsoft had ended support. In 2016, the NHS in Scotland reported Conficker infections. In 2017, some machines infected by WannaCry had first been infected by Conficker. The worm had become endemic in isolated industrial and healthcare networks where patching was difficult or where machines ran software tied to specific OS versions.
Conficker's technical innovations shaped both malware and defensive security for years. The DGA technique became standard in subsequent sophisticated malware families, forcing the development of DGA-detection tools. The peer-to-peer C2 mechanism was adopted and refined by banking trojans and espionage malware. The Conficker Working Group demonstrated that coordinated public-private response was possible and provided a model for later initiatives like the no-more-ransom project and coordinated botnet disruptions.
The worm that assembled a 15-million-machine botnet, evaded the most coordinated defensive response the internet had ever mounted, and then quietly sent a little spam - remained one of security history's most compelling unsolved questions. Who built it, why they built it, and what they actually intended to do with it was never established.