Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Storm: the largest botnet in the world?

Timely spam blasts help spread highly aggressive malware
By Cara Garretson , Network World , 09/28/2007
  • Share/Email
  • Tweet This
  • Comment
  • Print

Storm may not be the most creative or malicious piece of malware ever written, but it’s on track to become the most productive; threat researchers’ recent estimates put the number of PCs it has infected at more than 1 million.

First showing up on researchers’ radars about a year ago, Storm is defined by some as a worm, others as a Trojan Horse   See FAQ.  Though it has gone by many names, Storm — referring to the spam blasts it’s been behind that mention storms — has stuck.

Although Storm doesn’t use any particularly inventive or malicious techniques, such as erasing files on a hard drive or recording keystrokes to capture passwords and personal information, it has gained notoriety through its writers’ ability to update and adapt both the malware’s code and the spam blasts that lure people to become infected with it — all with the purpose of building a giant botnet.

“Storm is a very aggressive worm,” says John Levine, president of consulting firm Taughannock Networks and co-chair of the Internet Research Task Force's Anti-Spam Research Group. “It’s interesting because it uses a [peer-to-peer] control structure that makes it hard to kill.”

Most threat watchers say no one knows who is behind Storm, but Finnish antivirus maker F-Secure, which takes credit for giving Storm its name, says a group called the Zhelatin Gang is responsible and whom the company believes is operating out of Russia. F-Secure also says that Storm is the largest botnet in the world with just more than 1 million infected PCs; however, other researchers say there’s no way to know how many PCs have been infected.

Compared with highly destructive pieces of malware such as Slammer and Blaster that took down many computers and services, Storm sticks to mostly sending out spam and occasionally launching distributed denial-of-service (DoS) attacks, particularly against security companies that research the malware. But because of its size, Storm’s potential for harm is serious, says Patrik Runald, technical manager at F-Secure.

“As [Storm’s owners] have roughly 1 million computers under their control, we do have to take the threat of them attacking critical networks very seriously,” he says.

How Storm attacks

The way Storm secretly installs itself on PCs is via spam, but typically Storm is not carried by the message; instead the message attempts to get the recipient to visit a Web site that downloads the malware. It’s hard to avoid Storm-related spam, which was particularly active in late summer and shows no sign of stopping. These spam blasts take advantage of whatever the malware’s owners think would most entice recipients to click on the embedded link to a Web site purportedly related to the e-mail’s subject — be it a recent event such as the Labor Day weekend or the start of the football season or pop culture items such as computer games or a YouTube video clip.  

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comments (3)
Login
Forgot your account info?

RE: Storm: the largest botnet in the world?By user on October 1, 2007, 1:06 pmStorm has been in the news for weeks and countless articles have been written about it, this 4 page article, offers no new information other than saying that some...

Reply | Read entire comment

Cybercrime not bigger than the drug tradeBy Anonymous on October 1, 2007, 2:16 pmYou wrote: "Considering how profitable crime on the Internet has become, theres no reason to believe that Storm will die down; last month at a conference McAfee...

Reply | Read entire comment

Reminds me of some ofBy Anonymous on December 26, 2007, 2:58 pmReminds me of some of Gibson's work like Nueromancer and Mona Lisa Overdrive...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed