Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Virus alerts

July 17th, 2012, 12:50 GMT · By

Dutch Authorities Take Down C&C Servers Used by Third Largest Spam Botnet

SHARE:

Adjust text size:

FireEye researchers announce the takedown of two Grum C&C servers
Enlarge picture
After calling out to the security community in an effort to stop the activities of Grum, the world’s third largest spam botnet, FireEye researchers have announced the first victory. Dutch authorities have taken down two of the command and control (C&C) servers used by Grum.

“These two CnC servers were responsible for pumping spam instructions to their zombies. With these two servers offline, the spam template inside Grum's memory will soon time out and the zombies will try to fetch new instructions but will not able to find them,” FireEye’s Atif Mushtaq wrote.

“Ideally this should stop these bots from sending more spam. I am sure the absence of the spam sent by the world's third largest spam botnet will have a significant impact on the global volume.”

However, this is not the end of Grum. The main C&C servers, located in Russia and Panama, are still active and pulling the plug on them doesn’t appear to be an easy task.

The ISPs whose networks house the two servers have been contacted and presented with evidence which shows that there’s something crooked, but so far they've refused to take any action.

Unfortunately, these two master C&Cs can be used by the cybercriminals to recover their botnets by performing a worldwide update. FireEye researchers are permanently monitoring the situation and so far there haven’t been any attempts to recover the botnet.

The ideal scenario would be the one in which Russian and Panamanian authorities collaborated, such as the ones from the Netherlands.

In the meantime, security firms are also tackling ZeuS botnets and their masters. Not long ago, Microsoft added the names of two individuals to the complaint filed against the operators of the recently disrupted botnet.


1,305 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Trend Micro Confirms Yahoo! Mail Flaw Possible Cause of “Android Botnet”

Android “Botnet” Might Involve Yahoo! Mail Session Hijacking, Experts Say

Monkif Botnet Avoids Detection by Receiving Commands Encrypted in JPEG Files

All Carberp Cybercriminals Arrested, but Infection Rates Still High

Microsoft Reveals Names of Two Individuals in ZeuS Botnets Case

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM