Top 5 Botnets

Written by Sue Walsh on May 10, 2010

Here’s a look at the top 5 botnets and what they’re up to:

Compromised computers spew spam.

Compromised computers spew spam.

5. Bagle- This botnet has been around since 2004 and undergone many transformations. It now acts as a proxy for spammers. Its 500,000 or so zombies push out over 14 billion pieces of spam a day.

4. Rustock- This botnet was knocked offline by the McColo shutdown but roared back to life. It’s not known exactly how many zombies are under its control but it pumps out about 17 billion pieces of spam a day, most of it pharmaceutical and imaged based. It’s known for forging legit business newsletters to do its dirty work and also infests Twitter. Impressive considering the bot is only active for 4 hours a day!

3. Pushdo/Cutwail- This bot was born the same time as Storm, but has outlived it. Pushdo installs itself on the zombie computer and downloads Cutwail, which turns it into a spamming machine. Its 1.5 million zombies pump out 19 billion pieces of spam a day, most of it hawking fake pharmaceuticals, online casinos, malicious links and phishing schemes.

2. Bobax- Despite its small size (only 100,000 zombies) this botnet manages to pump out over 27 million pieces of spam a day. Its handlers are constantly adjusting it to make it harder and harder to trace and they appear to be renting the botnet out to spammers rather than doing the dirty work themselves.

1. Grum-  This botnet is super-sophisticated, acting as  both a botnet and a rootkit. It targets files used by  autorun registries and despite only having 600,000 zombies pumps out a whopping 40 billion spam messages a day, all of it hawking  various pharmaceuticals, which lately is by far the most popular kind of spam flooding the net.

  • (required)
  • (required)