Rustock Botnet: Dead, or just dazed?

Microsoft--working with legal and technical partners--has taken down the Rustock botnet

The Rustock botnet--one of the most prolific sources of spam--has gone silent. Microsoft worked with security vendors and the civil court system to pull the plug on Rustock. Some security experts question, though, if the absence of Rustock will have a significant impact on spam volume, or whether we have truly heard the last of Rustock, or if it is just dormant for a while.

Rustock is the same botnet that recently went silent--apparently taking a break for the 2011 holiday season. A post on the Microsoft on the Issues blog describes how Microsoft used the lessons learned from squashing the Waledac botnet last year to apply a combination of legal and technical methods for taking down the more vast and complex Rustock botnet.

The Microsoft post explains, "Rustock's infrastructure was much more complicated than Waledac's, relying on hard-coded Internet Protocol addresses rather than domain names and peer-to peer command and control servers to control the botnet. To be confident that the bot could not be quickly shifted to new infrastructure, we sought and obtained a court order allowing us to work with the U.S. Marshals Service to physically capture evidence onsite and, in some cases, take the affected servers from hosting providers for analysis."

The confiscated servers helped Microsoft and its partners knock Rustock offline, and are also providing valuable forensic evidence for security experts to analyze to learn more about the intricate inner-workings of the botnet infrastructure.

Symantec confirms that traffic from the Rustock botnet ceased as of 11:30am Eastern time on Wednesday, March 16. However, Symantec isn't confident that the absence of Rustock will have a significant impact on the volume of spam being spewed.

A Symantec spokesperson commented that, although Rustock has been a dominant source of spam--accounting for nearly half of all spam in 2010, it is too early to tell if killing Rustock has much effect. "In the last few months, other botnets have increased their output to match--or even exceed--that of Rustock. As a result, the takedown of this major botnet hasn't had much noticeable effect on the overall amount of spam and email traffic patterns appear normal.

AppRiver's Troy Gill is not so sure we have heard the last of Rustock. Gill notes that AppRiver did see a drop in spam levels as the Rustock command and control servers were disrupted, but adds "Interestingly, we have seen general, overall spam levels creep back to their previous levels in the past few hours. Although it is too early to tell for sure, this disruption appears to be temporary, similar to the 10-day disruption of Rustock back in November of 2010."

Whether it is permanent, or Rustock has the resilience to bounce back, Microsoft's ongoing efforts to combat this botnet and others--working with a team of legal and technical partners--is welcome, and it should be congratulated.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags Microsoftmalwarespamvirusesantispam

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Tony Bradley

PC World (US online)
Show Comments

Cool Tech

Bang and Olufsen Beosound Stage - Dolby Atmos Soundbar

Learn more >

Toys for Boys

Sony WF-1000XM3 Wireless Noise Cancelling Headphones

Learn more >

ASUS ROG, ACRONYM partner for Special Edition Zephyrus G14

Learn more >

Nakamichi Delta 100 3-Way Hi Fi Speaker System

Learn more >

Family Friendly

Philips Sonicare Diamond Clean 9000 Toothbrush

Learn more >

Mario Kart Live: Home Circuit for Nintendo Switch

Learn more >

Stocking Stuffer

Teac 7 inch Swivel Screen Portable DVD Player

Learn more >

SunnyBunny Snowflakes 20 LED Solar Powered Fairy String

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?