Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


01:54 PM
Connect Directly

Botnet Postmortem: Rustock Now Less Than Half The Size It Was At Takedown

New Microsoft report says Rustock victims likely infected with other malware, and still 'a long way to go' in cleaning up machines infected by the massive, now-defunct spamming botnet

It has been four months since Microsoft and federal authorities knocked the prolific spamming botnet Rustock offline, and some 700,000 of the estimated 1.6 million bots worldwide are still infected with its malware. A new Microsoft report published today based on intelligence it gathered from cleanup and removal of Rustock from infected bots also shows that Rustock-infected machines are typically riddled with other malware, as well.

Rustock, which was able to send some 30 billion spam email messages each day, including phony prescription drugs and fake Microsoft lottery scams, was crippled after seven Internet hosting locations in the U.S. were raided in the takedown operation in March. FireEye, researchers at the University of Washington, Pfizer, the Dutch High Tech Crime Unit, and the Chinese CERT all assisted in the operation.

Microsoft's Digital Crimes Unit and MMPC ran an experiment with the Win32/Rustock malware family of rootkit-enabled backdoor Trojans and found that within five minutes, multiple malware and unwanted software was downloaded onto a Rustock-infected machine. That confirmed Microsoft's suspicion that Rustock bots were likely infected with more than just Rustock's malware, Richard Boscovich, senior attorney for Microsoft Digital Crimes Unit, said in a blog post today.

The experiment used Win32/Harnig, a Rustock dropper, used for getting bots. "Within five minutes of installation, a wide variety of additional malware and potentially unwanted software had been downloaded and installed onto the infected computer -- and many of these threats are themselves designed to eventually download even more malware," Boscovich said.

Among the 19 other malware programs that had infested the machine was rogue adware, spyware, various Trojan downloaders, and a worm.

Meanwhile, Microsoft says the number of Rustock bots has been cut by 56.12 percent, with the most bots in India, with 99,032; followed by the U.S., with 55,731; Turkey, with 50,465; Italy, with 32,041; Russia, with 27,535; Germany, with 25,318; Brazil, with 21,967; France, with 21,625; Mexico, with 19,064; and Poland, with 18,015.

Russia had the highest rate of reduction in victims since Rustock was first taken down, with 70.61 percent of its machines getting cleaned up, followed by India, with 69.3 percent, and Brazil, with a reduction of 53.24 percent.

"In short, since the time of the initial takedown we estimate the Rustock botnet is now less than half the size it was when we took it down in March. That’s great news, and the infection reduction has happened much more quickly than it did for Waledac over a similar period of time last year, but we still have a long way to go," Microsoft's Boscovich said in his post.

Meanwhile, Microsoft Digital Crimes Unit researchers saw one Rustock bot send 7,500 spam emails in 45 minutes -- a rate of 240,000 spam emails a day.

A copy of the full report, "Special Edition Security Intelligence Report: Battling the Rustock Threat," is available for download here.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 4/7/2020
The Coronavirus & Cybersecurity: 3 Areas of Exploitation
Robert R. Ackerman Jr., Founder & Managing Director, Allegis Capital,  4/7/2020
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-04-08
A vulnerability in Juniper Networks Junos OS on vMX and MX150 devices may allow an attacker to cause a Denial of Service (DoS) by sending specific packets requiring special processing in microcode that the flow cache can't handle, causing the riot forwarding daemon to crash. By continuously sending ...
PUBLISHED: 2020-04-08
Juniper Networks Junos OS uses the subnet for internal communications between the RE and PFEs. It was discovered that packets utilizing these IP addresses may egress an EX4300 switch, leaking configuration information such as heartbeats, kernel versions, etc. out to the Internet, leading...
PUBLISHED: 2020-04-08
A race condition vulnerability on Juniper Network Junos OS devices may cause the routing protocol daemon (RPD) process to crash and restart while processing a BGP NOTIFICATION message. This issue affects Juniper Networks Junos OS: 16.1 versions prior to 16.1R7-S6; 16.2 versions prior to 16.2R2-S11; ...
PUBLISHED: 2020-04-08
A privilege escalation vulnerability in Juniper Networks Junos OS devices configured with dual Routing Engines (RE), Virtual Chassis (VC) or high-availability cluster may allow a local authenticated low-privileged user with access to the shell to perform unauthorized configuration modification. This...
PUBLISHED: 2020-04-08
On High-End SRX Series devices, in specific configurations and when specific networking events or operator actions occur, an SPC receiving genuine multicast traffic may core. Subsequently, all FPCs in a chassis may reset causing a Denial of Service. This issue affects both IPv4 and IPv6. This issue ...