iTnews
  • Home
  • News
  • Technology
  • Security

Storm botnet dies down

By Staff Writers
Oct 15 2008 10:06AM
Follow google news

The Storm botnet has stopped producing spam, but it is unlikely that its creators have simply given up and gone home, experts say.

Storm botnet dies down
According to analysis by the Marshal Threat Research and Content Engineering (TRACE) team, spam originating from the Storm botnet has been dwindling for months and finally ceased altogether in September 2008.

No one knows for sure how many computers Storm succeeded in infecting at its peak; industry estimates currently range from 500,000 to 1 million infected computers at the botnet’s height.

The Storm botnet is said to be the most successful botnet of its type, and was one of the first botnets to use ‘Malicious Spam’ tactics -- using spam to distribute malware -- on a mass scale.

It first came into prominence in January 2007, when the botnet’s creators spammed fake news headlines to entice web users into clicking on links that infected the user’s PC with malware.

One of the earliest such campaigns used a headline describing lethal storms in Europe, which led to the botnet receiving its now notorious name.

“Storm ... established the basic template for developing a spam empire that other botnets have since copied,” said Phil Hay, Lead Threat Analyst for Marshal’s TRACE Team.

“Whoever was behind Storm really set the benchmark at the time for the kind of scale that was achievable with a spambot.”

At its peak in September 2007, Storm was said to be responsible for 20 percent of the world’s spam, including fake e-greeting cards and spam about popular Internet sites such as YouTube.

Its success finally captured the attention of Microsoft. In September 2007, Microsoft began targeting Storm through the Malicious Software Removal Tool, which is estimated to have cleaned 274,372 computers in its first month.

Marshal’s TRACE team reported in January 2008 that Storm had dwindled in the face of competition and Microsoft’s efforts from 20 percent to just 2 percent of spam by volume in the space of four months.

Rival botnets such as Srizbi, Mega-D and Rustock had begun to surpass Storm. In May 2008, Marshal attributed more than 50 percent of all spam in circulation to Srizbi.

While the Storm botnet has no longer been found to be circulating spam, no one is clear on what precisely happened to Storm.

Some suggest that the botnet was sold or morphed into another botnet and still continues to produce spam.

“We have seen occasional surviving Storm bot peers still trying to communicate with each other but the Storm’s command and control servers are unresponsive,” Hay said. “Our data indicates that Storm has stopped.”

“A distinct possibility is that the creators of Storm have abandoned it in favor of a newer botnet that they have created,” he said. “If they have, it is possibly one of the top spam botnets that we continue to track. It seems unlikely that Storm’s creators simply gave up and went home.”

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Tags:
botnetmarshalsecuritystormteamtrace

Related Articles

  • Anthropic pulls Mythos-class models globally Anthropic pulls Mythos-class models globally
  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
Join our WhatsApp Channel

Partner Content

Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
You meet the security standard. Shame no one can see it
Promoted Content You meet the security standard. Shame no one can see it
From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Promoted Content From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic releases Mythos-class model for public use

Anthropic releases Mythos-class model for public use

Apple bumps up security in fresh operating system releases

Apple bumps up security in fresh operating system releases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.