This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here
by Alastair Stevenson
24 Jul 2012
The creators of the infamous Grum botnet managed to briefly bring the spam network back from the dead, before it was once again shutdown.
Security vendor FireEye reported the attempt to get the botnet back online took place on Monday.
"Over the weekend we found that the Ukrainian internet service provider (ISP) SteepHost removed the null route on three [command and control servers] that were taken down last week," wrote FireEye researcher Atif Mushtaq in a blog post.
"We immediately noticed this change and contacted SteepHost once again. After hours of negotiations, they eventually shut down these CnCs once more. During this time there was a short burst of spam sent by Grum, but it has disappeared as of this morning."
FireEye originally took down Grum on 19 July following a joint operation with spam-tracking service SpamHaus and local ISPs.
Grum is believed to have been the world's third largest botnet, with researchers estimating it was spitting out 18 billion spam messages a day at its peak.
Mushtaq warned that the botnet's operators may make a similar attempt to reactivate Grum in the near future, claiming the success of the operation would depend on ISPs.
"What are the odds that something like this will happen again? It's hard to predict at this time. Carel Van Straten of SpamHaus had a conversation with a SteepHost representative this morning. SteepHost assured him that something like this will not happen again," wrote Mushtaq.
"Interestingly, their excuses for letting these servers go online were break-ins and security-related issues. Funny, isn't it? They even claimed that this time they wiped out the CnC servers' hard drives. Wow, virtually destroying all of the evidence?"
Prior to Mushtaq's claim, Microsoft Trustworthy Computing director Tim Rains had issued a warning that Europe's cyber crime business is booming.
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
How concerned are you by the rising tide of cyber threats?
BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10
Updating your subscription status
Connect with V3.co.uk
It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model
BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs
PHP Developer £30,000 - £35,000 We are looking for...
Massive is looking for a diligent, motivated, fluent...
Corporate Treasurer - Banking London - £70k-£120k...
Product Manager – Insurance (Telematics) £40k-£50k...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree