Spam levels fluctuate as crooks try to revive botnets

While spam initially slid off a digital cliff, two weeks later it's unclear whether spammers have resumed their usual practices.

Two weeks after a hosting firm's shutdown sent global spam volumes plummeting, some researchers continue to claim that junk mail rates remain dramatically down, while others say spam has already bounced back.

The shutdown of California-based McColo, a company that hosted a staggering variety of cybercriminal activity, on Nov. 11 cut spam by as much as 75 percent in the first few days after its upstream Internet providers pulled the plug. The shutdown slashed spam volumes because some of the planet's biggest spam-sending botnets were controlled from servers hosted by McColo, according to security researchers who had long urged the company's disconnection from the Web.

While spam initially slid off a digital cliff, two weeks later it's unclear whether spammers have resumed their usual practices.

A researcher with IronPort Systems, a messaging security company owned by Cisco Systems, today said that spam is still down, if not out. According to IronPort, Tuesday's spam volume was approximately 72.7 billion messages, less than half of the 153 billion on Nov. 11, but up from the 64.1 billion of Nov. 13, two days after McColo went off the air.

"We're seeing small spikes in spam volumes relative to the post-McColo shutdown volumes," said Nick Edwards, a senior product manager at IronPort, in an e-mail Tuesday explaining the uptick. "We believe the spammers are trying other botnets -- those whose command-and-control infrastructure and front-end applications were not hosted by McColo."

They're not having much luck, Edwards added. "Spam volumes are still down significantly," he said. "While there was a temporary increase in spam volume [last] Friday and Saturday, spam volumes have not approached levels prior to the McColo shut down. The spammers are having a difficult time finding a botnet for lease that they can use effectively."

Researchers at rival MessageLabs Group -- now part of Symantec -- see the situation differently.

According to Matt Sergeant, a senior anti-spam technologist at the company, spam levels have bounced back to about two-thirds of what they were before McColo was yanked off the Internet. In fact, spam jumped to that volume only today.

Sergeant wasn't surprised by the lag time between McColo's shutdown and a return of spam. "The Asprox and Rustock botnets are back with a vengeance after having found new command and control [servers]," Sergeant said in an e-mail. "Cutwail never went away and it seems its owners have used the opportunity to increase output. Mega-D is also on the rise again."

Sergeant and Edwards, however, agreed on one thing: The Srizbi botnet looks gone for good.

"Srizbi, having once been responsible for 50% of all spam, is now completely defunct," said Sergeant, who added that sans that botnet, "spam levels won't return to what they had been."

Edwards confirmed that Srizbi was still offline. "And we have confirmation that McColo traffic has not been re-hosted somewhere else," he added. "The backers of both are still scrambling." McColo was still unavailable as of mid-afternoon Tuesday.

Srizbi, which also goes by "Mailer Reactor," was among the world's biggest botnets. In April, noted botnet researcher Joe Stewart of SecureWorks estimated Srizbi as composed of 315,000 infected PCs. The McColo takedown, Stewart said last week, had cut off more than half a million compromised computers -- aka "bots" -- from their criminal controllers.

Join the newsletter!

Or
Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags spammccolo

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Gregg Keizer

Computerworld
Show Comments

Essentials

James Cook University - Master of Data Science Online Course

Learn more >

Mobile

Victorinox Werks Professional Executive 17 Laptop Case

Learn more >

Exec

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?