Report: Other Spam Botnets Taking Over After Rustock’s Demise

Symantec Corp. recently announced the publication of its March 2011 MessageLabs Intelligence Report. Analysis reveals that in March, prior to its takedown, the Rustock botnet had been sending as many as 13.82 billion spam emails daily, accounting for an average of 28.5 percent of global spam sent from all botnets in March.

When the botnet ceased sending spam this month, global spam volumes fell by one-third. Since the notable Rustock takedown, other botnets have stepped up their activities to take advantage of the gap in the market. Bagle has now taken over from Rustock as the most active spam-sending botnet in 2011.

MessageLabs Intelligence identified that global spam volumes fell by 33.6 percent between March 15 and 17 following legal action against command and control hosts used by the Rustock botnet. In the days following the takedown of Rustock, spam accounted for approximately 33 billion emails per day, compared with an average of 52 billion per day in the previous week.

"It remains to be seen whether the criminals behind Rustock will be able to recover from this coordinated effort against what has become one of the most technically sophisticated botnets in recent years," said MessageLabs Intelligence Senior Analyst, Symantec.cloud, Paul Wood. "Rustock has been a significant part of the botnet and malware landscape since January 2006, much longer than many of its contemporaries."

Notably, Bagle did not appear in the top 10 spam-sending botnets at the end of 2010 as reported in the MessageLabs Intelligence 2010 Annual Security Report. By the end of 2010, Rustock had been responsible for as much as 47.5 percent of all spam, sending approximately 44.1 billion e-mails per day.

Also in March, MessageLabs Intelligence analyzed the spam traffic from the top ten major spam sending botnets. Since the end of 2010, the more-active Bagle botnet has sent approximately 8.31 billion spam emails each day, the majority linking back to pharmaceutical products. Bagle does not have as many bots under its control, or spikes of traffic as large and dominating as Rustock, but its output has been more consistent.

In March 83.1 percent of global spam was sent from botnets, an increase of 6.1 percentage points compared with the 77 percent at the end of 2010. During 2010, botnets sent an average of 88.2 percent of global spam.

"Botnets have been and remain a destructive resource for cyber criminals and through the years have become the spammers' air-supply, without which it would be very difficult for them to operate. Botnets are also used for other purposes such as launching distributed denial of service attacks, hosting illegal web site content on infected computers (known as bots), harvesting personal data from them and installing spyware to track the activities of their users," Wood said.

Other report highlights:

Spam: In March 2011, the global ratio of spam in email traffic from new and previously unknown bad sources decreased by 2 percent (1 in 1.26 emails).

Viruses: The global ratio of email-borne viruses in email traffic from new and previously unknown bad sources was one in 208.9 emails (0.479 percent) in March, an increase of .134 percentage points since February. In March, 63.4 percent of email-borne malware contained links to malicious websites, a decrease of .1 percentage points since February.

Endpoint Threats: The endpoint is often the last line of defense and analysis. The threats found here can shed light on the wider nature of threats confronting businesses, especially from blended attacks. Attacks reaching the endpoint are likely to have already circumvented other layers of protection that may already be deployed, such as gateway filtering.

Threats against endpoint devices such as laptops, PCs and servers may penetrate an organization in a number of ways, including drive-by attacks from compromised websites, Trojan horses and worms that spread by copying themselves to removable drives. Analysis of the most frequently blocked malware for the last month revealed that the Sality.AE virus was once again the most prevalent. Sality.AE spreads by infecting executable files and attempts to download potentially malicious files from the Internet.

MessageLabs deployed techniques such as heuristic analysis and generic detection, to correctly identify and block several variants of the same malware families, as well as identify new forms of malicious code that seek to exploit certain vulnerabilities that can be identified generically. Approximately 15.7 percent of the most frequently blocked malware last month was identified and blocked in this way, using endpoint security protection.

Phishing: In March, phishing activity was 1 in 252.5 emails (0.396 percent), a decrease of 0.065 percentage points since February.

Web security: Analysis of web security activity shows that an average of 2,973 websites each day were harbouring malware and other potentially unwanted programs including spyware and adware, a decrease of 27.5 percent since February. 37 percent of malicious domains blocked were new in March, a decrease of 1.9 percentage points since February. Additionally, 24.5 percent of all web-based malware blocked was new in March, a decrease of 4.2 percentage points since last month.

Geographical Trends:

  • Oman became the most spammed in March with a spam rate of 87.9 percent.
  • In the U.S. 79.6 percent of email was spam and 79.4 percent in Canada. The spam level in the UK was 79.1 percent.
  • In The Netherlands, spam accounted for 80.2 percent of email traffic, while spam levels reached 80 percent in Germany, 78.9 percent in Denmark and 78.8 percent in Australia.
  • Spam levels in Hong Kong reached 80.6 percent and 77.7 percent in Singapore. Spam levels in Japan were 76.4 percent.
  • In South Africa, spam accounted for 79.5 percent of email traffic.
  • Luxembourg became the most targeted by email-borne malware with 1 in 26.2 emails blocked as malicious in March. The sharp increase was a result of a large number of variants of Bredolab, Zeus and SpyEye malware, which was observed in a number of other countries, including South Africa.
  • In the UK, 1 in 98.8 emails contained malware. In the US virus levels were 1 in 507.9 and 1 in 160.1 for Canada. In Germany, virus levels reached 1 in 352.7, 1 in 916.8 in Denmark and 1 in 467.1 for The Netherlands.
  • In Australia, 1 in 261.0 emails were malicious and, 1 in 357.3 for Hong Kong, for Japan it was 1 in 1,015 compared with 1 in 823.8 for Singapore.
  • In South Africa 1 in 76.9 emails contained malicious content.

 Vertical Trends:

  • In March, the most spammed industry sector with a spam rate of 82.3 percent continued to be the Automotive sector.
  • Spam levels for the Education sector were 81 percent, 79.6 percent for the Chemical & Pharmaceutical sector, 79.8 percent for IT Services, 78.8 percent for Retail, 78.1 percent for Public Sector and 78 percent for Finance.
  • In March, Government/Public Sector remained the most targeted industry for malware with 1 in 27 emails being blocked as malicious.
  • Virus levels for the Chemical & Pharmaceutical sector were 1 in 302.2, 1 in 326.5 for the IT Services sector, 1 in 397 for Retail, 1 in 109.6 for Education and 1 in 318.9 for Finance.

Featured

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

  • Improve Incident Response With Intelligent Cloud Video Surveillance

    Video surveillance is a vital part of business security, helping institutions protect against everyday threats for increased employee, customer, and student safety. However, many outdated surveillance solutions lack the ability to offer immediate insights into critical incidents. This slows down investigations and limits how effectively teams can respond to situations, creating greater risks for the organization. Read Now

  • Security Today Announces 2025 CyberSecured Award Winners

    Security Today is pleased to announce the 2025 CyberSecured Awards winners. Sixteen companies are being recognized this year for their network products and other cybersecurity initiatives that secure our world today. Read Now

  • Empowering and Securing a Mobile Workforce

    What happens when technology lets you work anywhere – but exposes you to security threats everywhere? This is the reality of modern work. No longer tethered to desks, work happens everywhere – in the office, from home, on the road, and in countless locations in between. Read Now

  • TSA Introduces New $45 Fee Option for Travelers Without REAL ID Starting February 1

    The Transportation Security Administration (TSA) announced today that it will refer all passengers who do not present an acceptable form of ID and still want to fly an option to pay a $45 fee to use a modernized alternative identity verification system, TSA Confirm.ID, to establish identity at security checkpoints beginning on February 1, 2026. Read Now

New Products

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.