Custom Search
Search more than 150 trusted Websites for related information.

Rustock and Srizbi botnets share a common trojan

August 22, 2008 by Shanmuga  
Filed under Botnets

"Two of the world’s largest and most prolific spamming botnets have been spotted sharing a common bot malware-delivery method. But whether that means that the operators of the rival Rustock and Srizbi botnets are actually in cahoots is unclear, security researchers say.

Rustock, which recently edged Srizbi for the top slot as the biggest spammer mostly due to a wave of fake Olympics and CNN news spam, and Srizbi, known for fake video and DVD spam, have been using the same Trojan, Trojan.Exchanger, to download their bot malware updates, researchers say. “This is the first time” we had seen this connection between the two botnets, says Fengmin Gong, chief security content officer for anti-botnet software firm FireEye. “That’s why when we saw it, it was surprising.”" - Content courtesy of Rival Botnets Share a Common Bond, Researchers Find - Desktop Security News Analysis - Dark Reading

  • StumbleUpon
  • Digg
  • Reddit
  • del.icio.us
  • Facebook
  • MySpace
  • TwitThis
  • Google
  • Yahoo! Buzz
  • Live
  • YahooMyWeb
  • E-mail this story to a friend!

If you enjoyed this post, make sure you subscribe to my RSS feed!

You may also like to read

Comments

2 Responses to “Rustock and Srizbi botnets share a common trojan”

  1. bob on August 23rd, 2008 10:03 PM

    Amazing facts…
    So they are actually fooling the world…amazing these guys are doing these nasty things for so long and still federal agencies are helpless against them…

    Some more insight inside these botnets..this time FE guys talkin about their common cncs..

    http://blog.fireeye.com/research/2008/08/srizbi-and-ru-1.html

  2. Shanmuga on August 23rd, 2008 10:48 PM

    Thanks for sharing the link bob, the way fireeye connected the dots was really commendable!

Everyone has an Opinion...why don't you share yours and oh, if you want a pic to show with your comment, go get a gravatar! or you can even subscribe to our comments feed.

    Note:
  • All fields except the comments field are optional.
  • Real names aren't required, but please give us something to call you. Conversations among several people called "Anonymous" get too confusing.
  • All comments are pre-moderated, and will not appear on this site until approved by the site owner.





Tags

More News, Articles from elsewhere