Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Experts link flood of 'Canadian Pharmacy' spam to Russian botnet criminals

Operation reportedly responsible for half of all 'pharma' spam
By Ellen Messmer, Network World
July 16, 2009 05:20 PM ET
  • Share/Email
  • Tweet This
  • Comment
  • Print

The world's currently most voluminous spam generator, “Canadian Pharmacy,” is clogging networks with come-ons for male-enhancement drugs and painkillers -- and there’s growing belief it has a link to Russian cybercrime groups selling counterfeit medicines.

In this case, "Canadian Pharmacy," hyping itself as “the #1 Internet Online Drugstore,” is neither Canadian nor a pharmacy. In fact, "Canadian Pharmacy" doesn’t appear to exist as an established Web site but only a shifting hyperlink in a spam message generated by about eight crime botnets.

Spam volumes as a whole skyrocketed 60% between January and June to 150 billion messages a day, according to a report released this week by Marshal8e6, a vendor of Web and anti-spam security products, which says so-called “pharmaceutical spam,” or “pharma spam” for short, constitutes 75% of that.

About 83% of all spam today is generated by specialized botnets such as Rustock and Mega-D, according to Symantec’s MessageLabs division. Botnets are sophisticated command-and-control systems that exploit compromised computers and servers.

Spamming is one task botnets may be designed to do, and when it comes to pharma spam, "Canadian Pharmacy" is the spamiest, with half of the pharma volume, says Bradley Anstis, director of technical strategy at Marshal8e6.

"It's 65% of all global spam right now," says Adam Wosotowsky, principal engineer in messaging tactical response at McAfee, adding, "it's been surging since the end of last year."

Canadian Pharmacy spam changes in its content from time to time, and may sometimes looks like a newsletter with a fake AARP endorsement, says Wosotowsky.

Like many others, Anstis draws a connection between the massive volumes of "Canadian Pharmacy" spam and the Web site GlavMed.com that bills itself as a “pharmacy affiliate program” offering 30% to 40% commission fees on drugs sold.

“Every time you send your customers from your site to us, you earn up to 40% commission fee on each sale,” the GlavMed.com site advertises, claiming it doesn’t approve of sales methods involving spam. “We take charge of the entire shopping experience: fulfillment, customer service, and shipping, and we track the sales generated from your site.”

GlavMed.com, which didn't respond to requests for comment, is a domain name registered with Russian registrar Regtime Ltd.. under the registrant name Pharmos Limited in an address in Great Britain. The phone number, which when called offers no identification, accepts voicemail but no call was returned. While some pages on the GlavMed site are in English, the frequently asked questions are in Russian.

While Anstis is uncertain as to what GlavMed does, Cisco’s chief security researcher, Patrick Peterson, says it is a “criminal organization behind the pharmaceutical organization” that he learned quite a lot about while studying the activities of the Storm botnet last year.

Storm “makes a request every hour to GlavMed asking for the spam templates, the URL to be spammed and the address list,” says Peterson.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Partner Content

Gartner 2009 Magic Quadrant for Job Scheduling

Gartner has positioned BMC CONTROL-M in the Leaders Quadrant of their "2009 Magic Quadrant for Job Scheduling." The report assesses the ability to execute and completeness of vision of key vendors in the marketplace. Read a full copy today, courtesy of BMC Software.

Download whitepaper

Dell's SMART Approach to Workload Automation

Read a compelling case study by EMA, Inc. to learn how Dell uses BMC CONTROL-M to cut cost and increase productivity with workload automation.

Download whitepaper

Workload Automation Cost Savings 2 Minute Video

A major computer manufacturer uses BMC CONTROL-M and just four people to schedule and run over 85,000 jobs every month. By switching to BMC CONTROL-M, they more than quadrupled the workload without adding a single staff member.  See how in this 2-minute video overview.

Go to video

Comments (2)
Login
Forgot your account info?

ed hardyBy Anonymous on July 20, 2009, 4:54 amed hardy wallets/ luggage ed hardy watches ed hardy wristbands ed hardy

Reply | Read entire comment

Ed Hardy T-shirt, bags .hoodies , caps . watches .shoes. dress By wendy on July 21, 2009, 3:55 amWelcome to visit www.edfashions.com Hottest best price

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed