Feeds

Spam levels plummet as Rustock botnet taken down... for now

815,000 zombies with no master...

Top three mobile application threats

Spam volumes shrank on Wednesday after the prolific Rustock botnet fell silent, reportedly as a result of a takedown action.

Rustock, which is made up of a network of compromised (malware-infected) Windows PCs, turns an illicit income for its unknown controllers by being the biggest single source of global spam. The botnet is particularly active in advertising unlicensed net pharmacies, or at least it was until Wednesday afternoon, when its junk mail deluge ran dry.

Security blogger Bryan Krebs, who broke the story of the sudden drop-off, suggests the respite of spam from Rustock is the possible result of a takedown action against the zombie network's command and control system. "Dozens of internet servers used to coordinate these spam campaigns ceased operating, apparently almost simultaneously," he writes. "Such an action suggests that anti-spam activists have succeeded in executing possibly the largest botnet takedown in the history of the internet."

Details of who took this action are unclear at present, though security firms were able to confirm that Krebs is spot on in attributing a sharp drop in spam levels to the shut-down (at least temporarily) of Rustock.

M86 Security Labs, for example, said that Rustock control servers it monitors are unreachable. "It is unclear yet who or what caused the shutdown," the security firm said in a blog post on the Rustock shutdown that includes a graph of the botnet's junk mail output. "It's also possible it has been abandoned."

The Rustock botnet is made up of an estimated 815,000 compromised Windows PCs, controlled via a network of around 26 servers.

Infected machines are still pox-ridden but without instructions to act on and spam templates to drawn upon they have been rendered inert, at least for now. Rustock has been around for around three years and, at its peak, was to blame for half the spam in circulation.

Spam from Rustock previously fell away to almost nothing over the Christmas and New Year holiday before returning in mid-January, possibly as the result of a temporary break by the botherders controlling the network, so it would be unwise to write up Rustock's obituary just yet. Even if Rustock is properly dead, the business of using junk mail messages to spamvertise sites offered unlicensed pharmaceuticals is simply too lucrative to disappear anytime soon. Economic logic dictates that someone will move in and pick up the slack. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
Burnt out on patches this month? Oracle's got 104 MORE fixes for you
Mass patch for issues across its software catalog
Reddit users discover iOS malware threat
'Unflod Baby Panda' looks to snatch Apple IDs
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.