On TechRepublic: 3 habits of highly ineffective employees

Search:
Go!


See video that entertains and explains the latest in tech

Click Here
advertisement

Security Watch : Why spam isn't going away soon
Why spam isn't going away soon
(Hint: Blame the Storm worm)
By Robert Vamosi 
Senior editor, CNET Reviews
March 3, 2008

Recently, Symantec said in its February 2008 State of Spam report that 78.5 percent of all e-mail is spam; they also said most of that is now coming from Europe. That's a change from previous reports that had suggested servers in North America were responsible. What the Symantec report doesn't explicitly state is that much of the European spam doesn't come from individuals sitting at their desks pumping out lists. Europe is one of the hotbeds for the Storm worm botnet, notorious for automatically co-opting its victims into spam relays. For example, with the release of a Valentine's Day theme-spam barrage in early February, Dr. Jose Nazario of Arbor Networks estimated that Storm has grown by as much as 50 percent in new infections. More ominous, Nazario says, is "the fact (Storm) is generating lots of money means that it's in (the creator's) interests to keep grooming it, keep growing it." Worse Storm isn't the only big, bad botnet in town.

Mega-D
One new botnet that's making news is Mega-D. Nazario said that Mega-D got its name because the botnet is known to send out what is called in the business "enlargement spam." Think Viagra. Nazario said "This is a piece of malware that comes out typically on Friday afternoon, generally with a subject...telling you, for example, to go look at Angelina Jolie naked or Britney Spears having a fight with Angelina, things like that." He said the e-mail is sent primarily to Europe and North America. "Once people go ahead and have a look, they're nailed."

With the release of a Valentine's Day theme-spam barrage in early February, Dr. Jose Nazario of Arbor Networks estimated that Storm has grown by as much as 50 percent in new infections.

In February, a U.K. security company Marshal declared Mega-D the biggest source of new spam on the Internet, outpacing Storm. This brought a degree of skepticism from other security researchers, such as Joe Stewart of SecureWorks. He told the U.K.'s The Register that Mega-D had far less infections than Storm and wasn't spreading very fast.

Mega-D is really Storm Lite?
There's also speculation that Mega-D might be just be a dedicated subpartition of Storm. Nazario said Storm is one of the most high-profile of the active botnets to use encrypted command and control instructions, allowing the creators to lease off parts of the larger network to others. Fortunately, the encryption used by Storm isn't strong, and most researchers are able to access the data inside.

But without close examination of the malware code itself, Nazario said that can't yet be determined. Currently Marshal is working with Arbor Networks and others to determine what's what. Marshal spokesperson Phil Hay said in an e-mail to CNET "one thing is for sure, (Mega-D) is responsible for a huge amount of spam."

Marshal spokesperson Phil Hay said in an e-mail to CNET 'one thing is for sure, (Mega-D) is responsible for a huge amount of spam.'

MayDay
But Mega-D has company. Another security company, Damballa, has been tracking another spam producing botnet called MayDay. While the number of infections aren't anywhere close to Storm, MayDay has infiltrated some Fortune 500 networks, which gives some cause to worry because the actual number of infections could be higher.

MayDay uses HTTP to communicate, making the botnet harder to detect because the signal to noise ratio is much higher. Presently, HTTP bots appear to be limited to the Russian Federation and nearby countries, but Nazario and others wonder whether HTTP botnets could be the next big thing in criminal malware.

Security Bites Podcast
CNET.com's Robert Vamosi tells you about the latest security threats, what's coming, and how to protect your system. Listen now


CNET's free newsletters
Rob Vamosi's
award-winning
column on Internet threats and how to counter them 
Delivered Mondays


TalkBack
18 messages

Article discussion: Why spam isn't going away soon (Hint: Blame the Storm worm)


Latest post:

"Solution to Spam"
by dhayes501 (See profile) - April 9, 2008 3:15 PM PDT
This will eliminate Spam by removing forged headers and creating accountability.

This will require a small addition to the SMTP and POP3 protocols.

Whenever an email ... (Read more).
Sort by: Title |
Date
| Most helpful

No it won't go away.

Spam won't go away easily. This is same a junk mail in postal service. You can s... (Read more)
by baddawg65 (See profile) - March 5, 2008 11:23 AM PST
0 out of 1 users found this comment helpful

ISPs and owners of zombie PCs protect the spamers

Spam sent by botnets include both the location (IP address) of the sending compu... (Read more)
by hadaso (See profile) - March 5, 2008 12:53 AM PST
5 out of 5 users found this comment helpful

Spam safety?

What about a plugin for our e-mail readers that doesn't allow outgoing traffic? ... (Read more)
by DrNicket (See profile) - March 4, 2008 3:41 PM PST

Is sparm really a problem?

Spam virtually never gets through my combination of Outlook 2003 and f-Secure's ... (Read more)
by gdgroves (See profile) - March 4, 2008 1:52 PM PST

It's the people who get the spam who are to blame.

If fewer people fell for the schemes, we'd have far less spam out there. There ... (Read more)
by One-Eared Gundark (See profile) - March 4, 2008 10:44 AM PST
20 out of 20 users found this comment helpful | 1 comment

CAn someone explain the money trail?

"Follow the Money" said Deep Throat to Bernstein and Woodward. What I don't know... (Read more)
by c-mua (See profile) - March 4, 2008 10:34 AM PST

Reporting Spam

I used to get a ton of spam. Over 100 every morning. I have since started usin... (Read more)
by jimbo7149 (See profile) - March 4, 2008 9:51 AM PST
10 out of 10 users found this comment helpful | 2 comments

No European e-mail

I know no one outside of the USA. Why not have a way to block all mail from Euro... (Read more)
by lcole (See profile) - March 4, 2008 9:30 AM PST

i hate spam

Spam the letters from hell!! Two reasons why spam flourishes.

1. advertis... (Read more)
by wawadave (See profile) - March 4, 2008 9:22 AM PST
10 out of 20 users found this comment helpful


Copyright ©2008 CNET Networks, Inc. All rights reserved. Privacy policy|Terms of use