Feeds

MCI 'makes $5m a year from spam gangs'

Spamhaus accuses telco of aiding and abetting junk mailers

  • alert
  • submit to reddit

3 Big data security analytics techniques

Spamhaus has slammed MCI for hosting a website selling spamming software that is allegedly integral to the illegal trade in compromised PCs. The site - send-safe.com - sells spamware called Send Safe which uses broadband-connected PCs infected by viruses such as SoBig to distribute junk mail.

More than 70 per cent of spam comes from PCs infected with viruses or trojans, according to Spamhaus, a leading anti-spam organisation. By using compromised machines (proxies in spammer parlance) - instead of open mail relays or unscrupulous hosts - spammers can bypass basic anti-spam defences, such as IP address blacklists. Spamhaus reckons 80,000-100,000 new PCs every week are infected, leading to ever increasing volumes of spam. Spammers and their coding allies are coming up with new tricks to make the approach even more effective, with Send-Safe's developers as the forefront of this illegal activity.

The latest version of Send-Safe allows spammers to use hijacked proxies to send the spam out via the upstream ISP's main mail server, instead of from an infected machine itself. Ruslan Ibragimov, author of the 'Send-Safe'package, also sell lists of freshly-infected proxies to the spammer community, according to Spamhaus.

"MCI Worldcom not only know very well they are hosting the Send Safe spam operation, MCI's executives know send-safe.com uses the MCI network to sell and distribute the illegal Send Safe proxy hijacking bulk mailer, yet MCI has been providing service to send-safe.com for more than a year," writes Spamhaus director Steve Linford.

Timothy Vogel, who heads MCI's legal team for technology issues, told the Washington Post that MCI is only the wholesale provider of the web space used by Send Safe. He told the paper that MCI would take action if it had evidence that the Send-Safe company was spamming which "would violate MCI policy". But merely advertising its product is a form of speech that should not be censored, he said.

Linford said Vogel's interpretation of the law is incorrect. "While commercial speech is given qualified protection under the first amendment, advertising the sale of software designed for the prime purpose of allowing the end-user to engage in illegal activities is not protected under the first amendment," he said

"MCI have flatly refused to stop send-safe.com and other proxy spam gangs, which has allowed Send Safe to become one of the most sold anonymous proxy hijacking bulk mailers on the spam scene, and has had ever more spammers flocking to MCI," Linford added.

Spamhaus accuses MCI of being on the wrong side of the fight against junk mail not just by hosting send-safe.com but becoming a safe haven for spammers in general. MCI ISP tops Spamhaus's chart of 'Top 10 World Worst Spam Service ISPs'. It estimates MCI "earns upwards of $5m a year" from selling service knowingly to known spam gangs. ®

Related stories

US tops junk mail Dirty Dozen - again
VXers creating 150 zombie programs a week
Earthlink wins cash from spammers
Spam fighters infiltrate spam clubs
UUNet tops spammer-hosting super league

3 Big data security analytics techniques

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Reddit users discover iOS malware threat
'Unflod Baby Panda' looks to snatch Apple IDs
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.