Old and new botnets behind spam resurgence
Posted on 11 March 2013.
Bookmark and Share
Even when they have other capabilities, botnets are primarily used to send out malicious messages, since that is the easiest - not to mention the least risky - way for botmasters to earn money.


There are many botnets out there, and the number of computers enslaved into each varies day by day. McAfee's latest threat report pointed out that there is a continuing decline in global messaging botnet infections, but there are occasionally new spikes.

Bobax (alias Kraken), Donbot, Grum, Fivetoone, and Rustock have been abandoned for this or that reason, and are effectively dead, while the Bagle botnet is in its death throes, the numbers say.

Festi, Cutwail, Lethic, and Maazben are still out there, doing the work (read: damage) despite some setbacks, but the report shows they are in decline.

Finally, the botnets that are going through a renaissance are Darkmailer, Waledac, Slenfbot, and Kelihos.

"Darkmailer is a spam tool first released in 2003. Each month for three years a small number of senders has been systematically detected by our sensors. In January 2013, we saw a dramatic increase in senders–suggesting a possible evolution in its spamming technique," say McAfee researchers.

Waledac and Kelihos - the malware behind which is thought by some researchers to have the same author - have been hit and crippled by law enforcement actions.

Their botmasters have persevered and have doubled their efforts to bring them back to their former days of glory, but in the case of the Waledac botnet, its masters' efforts to use the Virut botnet to build a new Waledac one have been recently partially stymied by the Polish CERT:


Slenfbot is an IRC bot family known since 2008, and its recent proliferation is partially due to its distribution mechanism: links dropped in messages via chat, instant messaging applications and Facebook.










Spotlight

Review: Logging and Log Management

Posted on 22 May 2013.  |  Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.


Daily digest

By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
  

Weekly newsletter

With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.
  

 
DON'T
MISS

Thu, May 23rd
    COPYRIGHT 1998-2013 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //