The Inquirer-Home

Microsoft was behind the Rustock botnet takedown

Assisting law enforcement
Fri Mar 18 2011, 10:48

SOFTWARE FIRM Microsoft has revealed that it was behind a major crackdown on operators of the Rustock spam botnet, which saw email spam plummet as key computers were seized.

On Wednesday Microsoft's digital crimes unit along with US marshals raided web hosting firms in Kansas City, Scranton, Denver, Dallas, Chicago, Seattle and Columbus.

Microsoft had secured a federal court order allowing it to seize computers at these locations on the basis that they were alleged command and control machines for the infamous botnet.

The revelation of Microsoft's involvement in the surgical strike on Rustock was made after the Vole asked the courts to unseal the legal case it took to secure the court orders. The courts granted this request yesterday, according to the Wall Street Journal.

The Rustock botnet was responsible for nearly half of the world's spam, according to insecurity firm Symantec. Microsoft estimates that over one million computers across the globe have been hijacked to make up the botnet, sending out rafts of spam to millions of people every day.

Microsoft claims that its attack on the botnet has been completely effective. So far the deluge of spam from Rustock has stopped completely. µ

Share this:

Comments
A problem with that suggestion

If I use an illegal access method to make your computer tell you that it is vulnerable to an illegal access method, I myself am committing a crime.

Windows Update and Malicious Software Removal Tool are legitimate routes to find and disable malicious software on PCs. Or a specific cleanup tool. I don't use Microsoft's malicious software tool, in case they act on their apparent belief that Linux is malicious and illegal patent-busting software.

posted by : Robert Carnegie, 18 March 2011 Complain about this comment
Get the bots

This is a good job by Microsoft. But now they have the control systems, hopefully they can use it to message bot computers to flash warnings on screen, that they are infected and to clean themselves.

Otherwise other who were involved in the Bot net may be able re-recruit the bots using the bot clients / openings already in place.

Then Microsoft's work would all be for nothing. Also with the message could be a suggestion to use microsoft products to clean the PC's. Just saying...

posted by : Mat, 18 March 2011 Complain about this comment
aboutus
Advertisement
Subscribe to INQ newsletters
Advertisement
INQ Poll

Facebook starts selling shares

Will you buy Facebook shares?