This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Grum botnet briefly returns from the dead

by Alastair Stevenson

24 Jul 2012

View Comments

  • Tweet this
spam-spam-spam

The creators of the infamous Grum botnet managed to briefly bring the spam network back from the dead, before it was once again shutdown.

Security vendor FireEye reported the attempt to get the botnet back online took place on Monday.

"Over the weekend we found that the Ukrainian internet service provider (ISP) SteepHost removed the null route on three [command and control servers] that were taken down last week," wrote FireEye researcher Atif Mushtaq in a blog post.

"We immediately noticed this change and contacted SteepHost once again. After hours of negotiations, they eventually shut down these CnCs once more. During this time there was a short burst of spam sent by Grum, but it has disappeared as of this morning."

FireEye originally took down Grum on 19 July following a joint operation with spam-tracking service SpamHaus and local ISPs.

Grum is believed to have been the world's third largest botnet, with researchers estimating it was spitting out 18 billion spam messages a day at its peak.

Mushtaq warned that the botnet's operators may make a similar attempt to reactivate Grum in the near future, claiming the success of the operation would depend on ISPs.

"What are the odds that something like this will happen again? It's hard to predict at this time. Carel Van Straten of SpamHaus had a conversation with a SteepHost representative this morning. SteepHost assured him that something like this will not happen again," wrote Mushtaq.

"Interestingly, their excuses for letting these servers go online were break-ins and security-related issues. Funny, isn't it? They even claimed that this time they wiped out the CnC servers' hard drives. Wow, virtually destroying all of the evidence?"

Prior to Mushtaq's claim, Microsoft Trustworthy Computing director Tim Rains had issued a warning that Europe's cyber crime business is booming.

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

17%

55%

10%

9%

9%

Popular Threads

Powered by Disqus
BlackBerry Q5

BlackBerry Q5 video demo

BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

PHP Developer - £30,000 - £35,000

PHP Developer £30,000 - £35,000 We are looking for...

Senior Project Manager - must speak fluent German

Massive is looking for a diligent, motivated, fluent...

Corporate Treasurer - Banking - London

Corporate Treasurer - Banking London - £70k-£120k...

Product Manager – Insurance (Telematics)

Product Manager – Insurance (Telematics) £40k-£50k...

To send to more than one email address, simply separate each address with a comma.