Global effort stops half the world's spam

An international effort by spam fighters has taken down the infamous Grum botnet, slashing in half the worldwide amount of spam email.

Grum's last servers were taken offline in Russia on Wednesday, effectively killing the botnet that has no fallback mechanism, said Atif Mushtaq, a researcher at FireEye's security lab, which collaborated with the Russian Computer Security Incident Response Team and the Spamhouse Project in battling Grum.

At its height, Grum was the world's largest spam botnet, falling to No. 3 since January. Before the takedown, the botnet's120,000 malware-infected, active computers were spewing 18 billion spam email a day, or roughly a third of the world's spam, said Trustwave.

The impact of Grum's collapse went beyond the spambot. Stopping Grum caused a slowdown in the world's largest spam botnet, Lethic, Mushtaq said Thursday. "Due to this [international] community reaction, Lethic has gone underground for awhile."

With Grum down and Lethic quiet, the total amount of the world's spam has been cut in half, at least temporarily, said Mushtaq.

Aside from the numbers, the spam-fighters' success is expected to have a chilling effect on Russian and Ukrainian spam operations, which can no longer assume the countries offer a safe haven, due to weak laws.

The Grum operation was done without any involvement by law enforcement, showing that security researchers working together can also be effective in fighting botnets, which besides spam are used in denial of service attacks against websites.

With security researchers globally watching them, cybercriminals now have to deal with far more adversaries than in the past. "That will have a huge impact on the mindset of bot herders, and that may be the reason Lethic is going underground," Mushtaq said. Bot herder is the name given to people who control hijacked computers, or bots, in an illicit network.

Grum's death leaves tens of thousands of inactive, malware-infected computers. But without the original master computer and the IP addresses of the infected systems, the botnet is unlikely to be resurrected. "There's no way to hijack this botnet," Mushtaq said. "[the computers] are lost to us and to bot herders."

The Grum-killing operation started about two weeks ago when authorities in the Netherlands pulled the plug on two servers. This led to other servers in Panama being taken offline early this week.

In a cat-and-mouse game with spam fighters, the Grum operators launched more servers in Russia and the Ukraine. A service provider in Russia took the last of those computers off the Internet on Wednesday.

How long spam numbers will remain down is unclear. Spammers are sure to start filling the gap at some point. "Major takedowns can have a perceptible impact for weeks, even months, but that doesn't mean it will be the case here," David Harley, senior research fellow at ESET, said in an email.

Read more about malware/cybercrime in CSOonline's Malware/Cybercrime section.

Read more about malware/cybercrime in CSOonline's Malware/Cybercrime section.

Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

File Malware Protection System

File MPS analyzes network file shares to detect and quarantine malware brought into the network through the Web, email, or other manual means, such as online file sharing.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.