Rustock botnet edges Srizbi as number one spamming botnet, according to Marshal's TRACE team

Dark Reading Staff, Dark Reading

August 7, 2008

1 Min Read

A spam run that featured phony CNN headlines and Olympics “news” over the past few weeks has helped propel the Rustock botnet to become the world’s largest spamming botnet, according to researchers.

Rustock beat out the Srizbi botnet, which as of May was pumping out over 55 percent of all spam, according to Marshal’s TRACE team. Last week, 31.1 percent of all spam was sent by the Rustock botnet, versus 30.7 percent from Srizbi. And thanks mostly to Rustock’s rise, malicious spam rose from three percent to 32.3 percent of all spam, according to Marshal. “As time has gone on, the criminals behind Rustock have adjusted the appearance and sophistication of their messages to become more convincing at fooling recipients into infecting themselves,” said Phil Hay, lead threat analyst for Marshal’s TRACE team. “As Rustock has infected more machines, it has enabled the botnet to send more and more spam. These two factors have combined to push Rustock into first place and the volumes of malicious spam in circulation through the roof.” The fake news spam from Rustock began in late June, and was fairly rudimentary and easily spotted as spam, but later evolved into more sophisticated messages with headline links that led to fake codec updates laden with a Trojan. This week, Rustock sent a spam run that convincingly copied CNN’s format, with messages of a “CCN.com Daily Top 10” list of headlines, including topics on the Olympics. But Rustock’s method of infection was basically the same: a phony video that prompts the victim to update the codec. The executable file is the bot malware that recruits another machine for its botnet army.

— Kelly Jackson Higgins, Senior Editor, Dark Reading

Read more about:

2008

About the Author(s)

Dark Reading Staff

Dark Reading

Dark Reading is a leading cybersecurity media site.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights