Waledac Back to Its Old Habits

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Security researchers warn that after getting an overhaul on Christmas, then going silent at the beginning of January, the Waledac botnet has returned to sending pharma spam.

Waledac, widely considered to be the successor of the notorious Storm botnet, the top threat on the Internet during 2007 and 2008, was severely crippled by Microsoft in March 2010.

In Septmeber last year, a court awarded ownership of the 276 domains used for command and control purposes by the Waledac bot herders to the Redmond software giant and everyone believed that the botnet was history.

However, around Christmas, a new spam campaign began directing users to a site serving a piece of malware that displayed a lot of similarities to the trojan.

This led to security researchers calling the new threat Waledac 2.0. The almost one thousand computers infected with were mainly used for self-propagation through more spam.

But on around 5th or 6th of January the botnet suddenly went dead. No more spam traffic and no more active C&C domains.

"The reason of this blackout are not clear, however, about five days later (between the 10th and 11th of January) the botnet was up and spamming again," Symantec security expert Andrea Lelli, says.

"This is the same time as another old friend seems to have resurrected: the Rustock botnet has been reported to be back online with pharmaceutical spam. And guess what? Waledac is now spamming out pharmaceutical-related emails too! A suspicious coincidence indeed," the researcher adds.



Read more
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top