MS shuts down spam behemoth Rustock, reduces worldwide spam by 39%

fun4uoc

Supreme Member
Joined
Dec 25, 2007
Messages
1,205
Reaction score
1,049
My spam box has seemed noticeably light.

Source:
Code:
http://www.techamok.com/?pid=8842

Microsoft's Digital Crimes Unit, working with federal law enforcement agents, has brought down the world's largest spam network, Rustock. Rustock, at its peak, was a botnet of around 2 million spam-sending zombies capable of sending out 30 billion spam email per day. Microsoft's wholesale slaughter of Rustock could reduce worldwide spam output by up to 39%.

Rustock was taken down, piece by piece, in a similar way to the Mega-D botnet. First the master controllers, the machines that send out commands to enslaved zombies, were identified. Microsoft quickly seized some of these machines located in the U.S. for further analysis, and worked with police in the Netherlands to disable some of the command structure outside of the U.S.

With the immediate threat disabled, Microsoft then worked with upstream providers to black hole the IP addresses of whoever was controlling the botnet. To prevent further master controllers popping up, Microsoft worked with Chinese CN-CERT to block registration of domains that could be used by new command and control servers.

Finally, Microsoft is now working with ISPs and CERTs around the world to help clean the Rustock malware from around 1 million infected machines. It's also worth noting that Microsoft didn't do this alone; specialists from Pfizer, FireEye (the company behind the Mega-D botnet takedown), and the University of Washington helped out.
 
Interesting. However, this network was the replacement of another replacement of another... Everytime they shut down the big guns, there's a noticeable decrease in spam only to steadily climb back. Where there's money to be made, someone's fall is seen by others as an opportunity (IMO).
 
Damn, My Dick Pills are getting low, I was looking to re-order.

Well PM me and well work something out. No one should be left alone becouse their little (literally) brother down there.

Well good job from people getting down whole operation :P guess someone is going to lose lots of money.
 
It's amazing to see little bits and pieces of news like this and to recognize that there really are hackers and computer wizs out there who do all of the cool stuff that we see in movies, they just go undetected and it's not as extravagant. I mean, if you think about it, the owners of that network must have been banking a lot of money. The amount of money they could pull in by simply issuing a few commands is amazing.

ruwqon.png

Interesting. However, this network was the replacement of another replacement of another... Everytime they shut down the big guns, there's a noticeable decrease in spam only to steadily climb back. Where there's money to be made, someone's fall is seen by others as an opportunity (IMO).

I agree there. Botnets are all the rage these days. :p
 
Waste of time and money!

They will just come back take over again..

With all the money they made, they can afford to pay the best and roll out the spam once more...

Bill should be more worried about his shitty operating system..
 
Its harder to set up something like this again, for the following reasons:
The loophole which the malware uses gets recognized, their command structure gets recognized and it gets detected by AVs.

So in order to start again, they have to:
relocate themselves for legal reasons
rewrite the whole botnet
crypt to make it fud.

and then find exploits in third party software to fast track its spreading.. its a lot of work if you ask me...
 
Had no idea Pfizer had anti spam specialists. Must want you to pay full price for those penis pills.
 
so i think huge botnets will appear again and again.
there will always be some ways to trick av software (and to fool users, because there is a twist with social engineering). and with the growth of mobile apps market there will be more opportunities for the blackhat.

btw, it wasn`t mentioned, that they captured someone during the operation? only servers, IPs and domain names, so the owners will take some lessons for the next hop.

it`s like bullet and armor.
 
Back
Top