Skip this advertisement >
Please wait while the page is being loaded
Saturday | 5 July, 2008
ARN

Parasitic botnet spams 60 billion a day
Srizbi sends 50 percent of spam
Darren Pauli (Computerworld) 08 May, 2008 11:42:33

Related Stories
  • +

    Storm: The largest botnet in the world? 02 October, 2007 11:48:41

    Researchers say the Storm malware may be the world's "most productive" virus, with more than 1 million PC infections
    Storm may not be the most creative or malicious piece of malware ever written, but it's on track to become the most productive; threat researchers' recent estimates put the number of PCs it has infected at more than 1 million.
Additional Resources
ARN Library

Newsletter Subscription

Sign up for our ARN newsletters!
The premier provider of daily news to the IT channel, covering business, technology, products, and services.
RSS Feeds

The Srizbi botnet has stormed over its competition to become the Internet's biggest spammer.

Researchers claim the botnet is responsible for 50 percent of all spam, and is the biggest of its kind in history.

It's 300,000 zombie computers are being worked hard. The much larger Storm Worm required about 500,000 nodes - with some figures even suggesting anywhere between 1 million to 50 million -- to deliver 30 percent of global spam.

Joe Stewart, director at US consultancy Secure Works, said the Srizbi Trojan is the biggest botnet in history and the most powerful. He said Srizbi, aka "Cbeplay" and "Exchanger", can blast out 60 billion messages a day.

Storm is now in a tea cup after its spam output was cut down to a mere 2 percent, due to widespread media coverage which kicked off a race by security vendors to squash the threat.

Trojan.Srizbi is one of the first full-kernel pieces of malware, according to Symantec. It hides itself as a rootkit and operates completely within the kernel, without any interaction in user mode.

The Trojan is rumoured to contain code capable of uninstalling competing rootkits.

Marshall vice president of products, Bradley Anstis, said the Srizbi botnet has grown quickly to overtake the rival Mega-D botnet since the start of the year.

"Srizbi is the single greatest spam threat we have ever seen. Srizbi now produces more spam than all the other botnets combined," Anstis said.

"As Mega-D went offline, Srizbi stepped in to fill the gap and hasn't looked back since."

Mega-D rose quickly to prominence earlier this year after security researchers reported the Viagra-spruiking botnet had topped Storm's peak spam output by 30 percent.

"It is probable the [Mega-D] spammers got spooked and decided to lay low for a while, security researchers were close to discovering their control servers when the plug was pulled," Anstis said.

"Typically the spammers like the 'low and slow' approach; building their botnet up over time and trying to stay under the radar to avoid detection. It is an intriguing chain of events that."

The Rustock botnet has taken the second spot as the most notorious spammer, Mega-D third, followed by Hacktool.Spammer, Pushdo and Storm. Marshall estimates about 15 percent of spam is from other sources.

Srizbi has been documented spruiking watches, pens and of course Viagra.

ARN Directory | Vendors relevant to this article
Market Place

ARN Member Login

 
Panel Sessions
  • ARN Panel Sessions: Day 3

    The last of our panel sessions recorded live at CeBIT 2008. Today, the topic is storage. Data is growing at an enormous rate, so what does the future hold?

Play
ARN news
Play
Channel Watch
  • Brian's bloopers

    It takes a long time to produce an episode of Channel Watch. Maybe you'll understand why after watching this...

Play
Business Continuity & Disaster Recovery Zone

When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
ARN Vendor Directory
ARN Library

Dimension Data, La Trobe University and Windows Server 2008 partner to improve compliance

La Trobe University partnered with Dimension Data to deploy Windows Server 2008 and Network Access Protection technology to improve their existing network security solution.

Sponsored Links