Festi botnet takes over following Grum shutdown

Festi botnet takes over following Grum shutdown

تاریخ ایجاد

ID: IRCNE2012081586
Date: 2012-08-18

According to “ComputerWorldUK”, Festi, a relatively new botnet, has taken up the slack left by the shutdown in July of another major spamming botnet called Grum, according to the junk mail fighting organisation Spamhaus.
The Festi botnet, also called Spamnost, has surged since the demise of Grum. Spamhaus counts at least 250,000 unique IP addresses showing signs of a Festi infection, up from around 20,000 unique IP addresses preceding Grum's takedown by security researchers.
"Since the beginning of July, the Spamhaus XBL [Exploit Block List] has seen a huge increase in Festi spamming activities," said Spamhaus' Thomas Morrison. "At the peak, during one 24-hour period the XBL detected nearly 300,000 IP addresses that were infected with Festi, out of a total of one million that were infected with some sort of spam-sending bot.
Festi, which Symantec detected in December 2011, is now competing with Cutwail to be the most prolific spamming botnet. Festi's rise follows a familiar pattern: As security researchers, vendors and law enforcement have notched more successes in technically interfering with botnets and taking their infrastructure offline, spammers quickly move to other botnets.
Grum, which was sending 18 billion spam messages daily, was the latest major botnet to be shut down. Grum's command-and-control servers in Panama and the Netherlands were taken offline. Grum operators quickly set up command-and-control servers in the Ukraine, suing one of the remaining servers in Russia to redirect the infection bots.

Related Posts:
Experts take down the world's third largest botnet

برچسب‌ها