Feeds

Spam levels plummet as Rustock botnet taken down... for now

815,000 zombies with no master...

Security for virtualized datacentres

Spam volumes shrank on Wednesday after the prolific Rustock botnet fell silent, reportedly as a result of a takedown action.

Rustock, which is made up of a network of compromised (malware-infected) Windows PCs, turns an illicit income for its unknown controllers by being the biggest single source of global spam. The botnet is particularly active in advertising unlicensed net pharmacies, or at least it was until Wednesday afternoon, when its junk mail deluge ran dry.

Security blogger Bryan Krebs, who broke the story of the sudden drop-off, suggests the respite of spam from Rustock is the possible result of a takedown action against the zombie network's command and control system. "Dozens of internet servers used to coordinate these spam campaigns ceased operating, apparently almost simultaneously," he writes. "Such an action suggests that anti-spam activists have succeeded in executing possibly the largest botnet takedown in the history of the internet."

Details of who took this action are unclear at present, though security firms were able to confirm that Krebs is spot on in attributing a sharp drop in spam levels to the shut-down (at least temporarily) of Rustock.

M86 Security Labs, for example, said that Rustock control servers it monitors are unreachable. "It is unclear yet who or what caused the shutdown," the security firm said in a blog post on the Rustock shutdown that includes a graph of the botnet's junk mail output. "It's also possible it has been abandoned."

The Rustock botnet is made up of an estimated 815,000 compromised Windows PCs, controlled via a network of around 26 servers.

Infected machines are still pox-ridden but without instructions to act on and spam templates to drawn upon they have been rendered inert, at least for now. Rustock has been around for around three years and, at its peak, was to blame for half the spam in circulation.

Spam from Rustock previously fell away to almost nothing over the Christmas and New Year holiday before returning in mid-January, possibly as the result of a temporary break by the botherders controlling the network, so it would be unwise to write up Rustock's obituary just yet. Even if Rustock is properly dead, the business of using junk mail messages to spamvertise sites offered unlicensed pharmaceuticals is simply too lucrative to disappear anytime soon. Economic logic dictates that someone will move in and pick up the slack. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.