Rustock and Srizbi botnets share a common trojan
August 22, 2008 by Shanmuga
Filed under Botnets
"Two of the world’s largest and most prolific spamming botnets have been spotted sharing a common bot malware-delivery method. But whether that means that the operators of the rival Rustock and Srizbi botnets are actually in cahoots is unclear, security researchers say.
Rustock, which recently edged Srizbi for the top slot as the biggest spammer mostly due to a wave of fake Olympics and CNN news spam, and Srizbi, known for fake video and DVD spam, have been using the same Trojan, Trojan.Exchanger, to download their bot malware updates, researchers say. “This is the first time” we had seen this connection between the two botnets, says Fengmin Gong, chief security content officer for anti-botnet software firm FireEye. “That’s why when we saw it, it was surprising.”" – Content courtesy of Rival Botnets Share a Common Bond, Researchers Find – Desktop Security News Analysis – Dark Reading


















Amazing facts…
So they are actually fooling the world…amazing these guys are doing these nasty things for so long and still federal agencies are helpless against them…
Some more insight inside these botnets..this time FE guys talkin about their common cncs..
http://blog.fireeye.com/research/2008/08/srizbi-and-ru-1.html
Thanks for sharing the link bob, the way fireeye connected the dots was really commendable!