NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Spam Reports

Spam Reports


Two Major Botnets Possibly Controlled by the Same Bot Herder

Although the theory is arguable

By Denisa Ilascu, Internet / SEO News Editor

21st of August 2008, 12:32 GMT

Adjust text size:


Some researchers believe that the same man stands behind the Srizbi and Rustock botnets
Enlarge picture
It has been discovered that two of the botnets that are responsible for the largest number of spam attacks, Srizbi and Rustock, share the same principle when it comes to malware spreading. They both use Trojan.Exchanger, a type of malware that comes with unsolicited email. Each time users decide to check what's behind certain intriguing advertisements or unbelievable breaking news headlines, their machines get infected. Unknowingly, users get into a botnet that uses their computers to send tens, hundreds or even thousands of spam messages to other email accounts.

"The rise in malicious spam and the rise of Rustock are directly linked. Rustock has grown through malicious spam. Its success in infecting more computers through malicious spam has bred further success. It has been able to send even more spam in a kind of ever-increasing cycle." explains Phil Hay, lead threat analyst for Marshal's TRACE Team for MarketWatch. The other botnet also exploits people's naivety and grows at increasing speed.

Due to the resemblances between the two botnets, some claim that the spam networks are, in fact, being managed by the same man or criminal ring. "Some malware researchers have described Srizbi and Rustock as rival botnets, our data indicates that this apparent rivalry is a sibling rivalry at best. Srizbi and Rustock seem to be supported (controlled) by the same parent (bot herder)." comments a FireEye researcher on the official blog of the company.

Other specialists don't agree with the theory and rather believe that a major spammer is using both botnets to be harder to identify. "Maybe their bots are getting blacklisted faster when they're sending out URLs with fake video files because they're easy to spot, so their spam doesn't get through. So they send malware from this botnet, and spam from this one, to keep out of the blacklists longer." Joe Stewart, director of security research for SecureWorks said for DarkReading.

TAGS:

Srizbi | Rustock | bot herder | spam | malware
Read by 1,059 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Very Good (4.0/5) 1 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Shadow Botnet Creator Arrested in the Netherlands

McAfee Advises on How to Avoid Spam

New Trojan Guaranteed to Bypass Detection

Srizbi Accounts for Half of All Spam

Meet Srizbi, the Largest Botnet Ever

User opinions:


Comment #1 by: AM on 21 Aug 2008, 17:41 GMT reply to this comment

Well I guess Joe is missing the point here. It is the Rustock which is sending spam to fool readers to download these so called video plug-in i.e. Trojan.Exchanger.

Trojan.Exchanger itself is not capable of sending SPAM or spreading itself or other piece of malwares.

Its not complicated like which came first Egg or a chicken. It happens like this.

1. Rustock is sending SPAM emails containing links to fake video plugins i.e. Trojan.Exchanger.

2. Trojan.Exchanger has been further seen to download Srizbi and Pushdo.

So indirectly Rustock is facilitating the spread of Srizbi and Pushdo...its simple…..


Comment #2 by: Atif_Mushtaq on 22 Aug 2008, 08:01 GMT reply to this comment

Some more facts...

http://blog.fireeye.com/research/2008/08/srizbi-and-ru-1.html

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM