August 7, 2008
A spam run that featured phony CNN headlines and Olympics “news” over the past few weeks has helped propel the Rustock botnet to become the world’s largest spamming botnet, according to researchers.
Rustock beat out the Srizbi botnet, which as of May was pumping out over 55 percent of all spam, according to Marshal’s TRACE team. Last week, 31.1 percent of all spam was sent by the Rustock botnet, versus 30.7 percent from Srizbi. And thanks mostly to Rustock’s rise, malicious spam rose from three percent to 32.3 percent of all spam, according to Marshal. “As time has gone on, the criminals behind Rustock have adjusted the appearance and sophistication of their messages to become more convincing at fooling recipients into infecting themselves,” said Phil Hay, lead threat analyst for Marshal’s TRACE team. “As Rustock has infected more machines, it has enabled the botnet to send more and more spam. These two factors have combined to push Rustock into first place and the volumes of malicious spam in circulation through the roof.” The fake news spam from Rustock began in late June, and was fairly rudimentary and easily spotted as spam, but later evolved into more sophisticated messages with headline links that led to fake codec updates laden with a Trojan. This week, Rustock sent a spam run that convincingly copied CNN’s format, with messages of a “CCN.com Daily Top 10” list of headlines, including topics on the Olympics. But Rustock’s method of infection was basically the same: a phony video that prompts the victim to update the codec. The executable file is the bot malware that recruits another machine for its botnet army.
— Kelly Jackson Higgins, Senior Editor, Dark Reading
Read more about:2008
About the Author(s)
You May Also Like
Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and PhishingNov 01, 2023
SecOps & DevSecOps in the CloudNov 06, 2023
What's In Your Cloud?Nov 30, 2023
Everything You Need to Know About DNS AttacksNov 30, 2023