Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

Parasitic botnet spams 60 billion a day

Srizbi botnet is responsible for 50 percent of all spam and is the biggest of its kind in history, researchers say


The Srizbi botnet has stormed over its competition to become the Internet's biggest spammer.

Researchers claim the botnet is responsible for 50 percent of all spam, and is the biggest of its kind in history.

It's 300,000 zombie computers are being worked hard. The much larger Storm Worm required about 500,000 nodes - with some figures even suggesting anywhere between 1 million to 50 million -- to deliver 30 percent of global spam.

Joe Stewart, director at U.S. consultancy Secure Works, said the Srizbi Trojan is the biggest botnet in history and the most powerful. He said Srizbi, aka "Cbeplay" and "Exchanger," can blast out 60 billion messages a day.

Storm is now in a tea cup after its spam output was cut down to a mere 2 percent, due to widespread media coverage which kicked off a race by security vendors to squash the threat.

Trojan.Srizbi is one of the first full-kernel pieces of malware, according to Symantec. It hides itself as a rootkit and operates completely within the kernel, without any interaction in user mode.

The Trojan is rumored to contain code capable of uninstalling competing rootkits.

Marshall vice president of products, Bradley Anstis, said the Srizbi botnet has grown quickly to overtake the rival Mega-D botnet since the start of the year.

"Srizbi is the single greatest spam threat we have ever seen. Srizbi now produces more spam than all the other botnets combined," Anstis said.

"As Mega-D went offline, Srizbi stepped in to fill the gap and hasn't looked back since."

Mega-D rose quickly to prominence earlier this year after security researchers reported the Viagra-spamming botnet had topped Storm's peak spam output by 30 percent.

"It is probable the [Mega-D] spammers got spooked and decided to lay low for a while, security researchers were close to discovering their control servers when the plug was pulled," Anstis said.

"Typically the spammers like the 'low and slow' approach; building their botnet up over time and trying to stay under the radar to avoid detection. It is an intriguing chain of events that."

The Rustock botnet has taken the second spot as the most notorious spammer, Mega-D third, followed by Hacktool.Spammer, Pushdo and Storm. Marshall estimates about 15 percent of spam is from other sources.

Srizbi has been documented selling watches, pens and of course Viagra.

Computerworld Australia is an InfoWorld affiliate.


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





Virtualization: A Step by Step Approach to Success
Your virtual machines can be up and running in a matter of minutes. HP and Citrix have integrated XenServer with HP ProLiant servers and management tools, powered by hardware-assisted Intel Virtualization Technology to enable high- performance, cost-savings solutions for server consolidation and disaster recovery. Sponsor: HP

»  Click here to view this Webcast
  Storage is big, and getting bigger
The only certainty is that your requirement for storage will never be satisfied. While you clean out space and authorize POs, you might consider another alternative: outsourcing. The best way to deal with storage might be to let someone else deal with it. Sponsored by SGI

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS  IT EXEC-CONNECT   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist