Skip the navigation
News

Spam levels fluctuate as crooks try to revive botnets

Some researchers say spam still down, others see it bouncing back

By Gregg Keizer
November 25, 2008 12:00 PM ET

Computerworld - Two weeks after a hosting firm's shutdown sent global spam volumes plummeting, some researchers continue to claim that junk mail rates remain dramatically down, while others say spam has already bounced back.

The shutdown of California-based McColo Corp., a company that hosted a staggering variety of cybercriminal activity, on Nov. 11 cut spam by as much as 75% in the first few days after its upstream Internet providers pulled the plug. The shutdown slashed spam volumes because some of the planet's biggest spam-sending botnets were controlled from servers hosted by McColo, according to security researchers who had long urged the company's disconnection from the Web.

While spam initially slid off a digital cliff, two weeks later it's unclear whether spammers have resumed their usual practices.

A researcher at IronPort Systems Inc., a messaging security company owned by Cisco Systems Inc., today said that spam is still down, if not out. According to IronPort, Tuesday's spam volume was approximately 72.7 billion messages, less than half of the 153 billion on Nov. 11, but up from the 64.1 billion of Nov. 13, two days after McColo went off the air.

"We're seeing small spikes in spam volumes relative to the post-McColo shutdown volumes," said Nick Edwards, a senior product manager at IronPort, in an e-mail Tuesday explaining the uptick. "We believe the spammers are trying other botnets -- those whose command-and-control infrastructure and front-end applications were not hosted by McColo."

They're not having much luck, Edwards added. "Spam volumes are still down significantly," he said. "While there was a temporary increase in spam volume [last] Friday and Saturday, spam volumes have not approached levels prior to the McColo shutdown. The spammers are having a difficult time finding a botnet for lease that they can use effectively."

Researchers at rival MessageLabs Ltd. -- now part of Symantec Corp. -- see the situation differently.

According to Matt Sergeant, a senior antispam technologist at the company, spam levels have bounced back to about two-thirds of what they were before McColo was yanked off the Internet. In fact, spam jumped to that volume only today.

Sergeant wasn't surprised by the lag time between McColo's shutdown and a return of spam. "The Asprox and Rustock botnets are back with a vengeance after having found new command and control [servers]," Sergeant said in an e-mail. "Cutwail never went away and it seems its owners have used the opportunity to increase output. Mega-D is also on the rise again."

Sergeant and Edwards, however, agreed on one thing: The Srizbi botnet looks gone for good.

"Srizbi, having once been responsible for 50% of all spam, is now completely defunct," said Sergeant, who added that without that botnet, "spam levels won't return to what they had been."

Edwards confirmed that Srizbi was still offline. "And we have confirmation that McColo traffic has not been re-hosted somewhere else," he added. "The backers of both are still scrambling." McColo was still unavailable as of midafternoon Tuesday.

Srizbi, which also goes by "Mailer Reactor," was among the world's biggest botnets. In April, noted botnet researcher Joe Stewart of SecureWorks Inc. estimated Srizbi as composed of 315,000 infected PCs. The McColo takedown, Stewart said last week, had cut off more than half a million compromised computers -- a.k.a. "bots" -- from their criminal controllers.

Read more about Malware and Vulnerabilities in Computerworld's Malware and Vulnerabilities Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Malware and Vulnerabilities White Papers
Reducing the Cost and Complexity of Web Vulnerability Management
Hackers and cybercriminals are constantly refining their attacks and targets; which means you need agile tools to stay ahead of them.

Download this...
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
All Malware and Vulnerabilities White Papers
Malware and Vulnerabilities Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All Malware and Vulnerabilities Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs