41% of spam sent via Rustock botnet

Posted by   Virus Bulletin on   Aug 26, 2010

Botnet spam back after short summer break.

In its latest intelligence report, security firm MessageLabs reports that 41% of all spam is being sent through the Rustock botnet, an increase of 9% since April. The botnet sends an estimated 32 million spam emails per minute.

Interestingly, the number of bots controlled by Rustock's botherders has almost halved in the same period. One of the reasons for this apparent contradiction appears to be the drop in the use of TLS for sending the spam.

TLS makes use of an encrypted connection to send the messages and botherders may have believed this would decrease the chances of their messages being intercepted; in April, 30% of all spam and 70% of Rustock spam was send using TLS. However, TLS significantly slows down the connection, and with now less than 0.2% of spam being sent over TLS connections, spammers seem to have realised that their delivery rates were being significantly impacted by its use.

Currently 92.2% of all email is spam - an increase of 3.3% since July; 95% of these spam messages are sent via botnets. The relatively low spam ratio in July is explained by a temporary drop in spam coming from a number of botnets, most notable the Grum botnet.

In August, Grum's output increased again and it now takes up second position among the most prolific spamming botnets, with over 16% of spam sent through its bots. While Rustock has mostly infected computers in Western countries, Grum's bots are more likely to be found in Russia, India and Vietnam.

The full MessageLabs report can be found here (PDF), with comments on how this affects those sending legitimate email at the Word to the Wise blog here.

Posted on 26 August 2010 by Virus Bulletin

twitter.png
fb.png
linkedin.png
googleplus.png
reddit.png

 

Latest posts:

Call for Papers: VB2017

We have opened the Call for Papers for VB2017. We are particularly interested in receiving submissions from those working outside the security industry itself.

Ransomware not a problem for half of businesses

According to a report by IBM Security, 70 per cent of businesses that are the victim of a ransomware attack end up paying the ransom. However, the report also suggests that a little over half of businesses manage to avoid getting infected at all,…

Ransomware would be much worse if it wasn't for email security solutions

The latest VBSpam test brings good news: at least 199 out of every 200 emails containing a malicious attachment were blocked by email security solutions. All of the full solutions tested achieved a VBSpam award, with five earning a VBSpam+ award.

Throwback Thursday: The malware battle: reflections and forecasts

"Another year has come to its end and the malware battle still rages on." In January 2004, Jamz Yaneza reflected on the year just ended and pondered what the coming year would have in store for the AV industry.

VB2016 paper: Open Source Malware Lab

At VB2016, ThreatConnect Director of Research Innovation Robert Simmons presented a paper on setting up an open source malware lab. Today, we share the accompanying paper and video.