Microsoft Helps Shut World's Largest Spam Network

In conjunction with federal law enforcement agencies, Microsoft's Digital Crimes Unit (DCU) announced on Thursday that it had helped pulled the plug on the Rustock spybot network.

The botnet ring had controlled more than 1 million computers, sending billions of spam e-mails per day, according to Microsoft. The takedown wasn't the first, as the DCU also succeeded in hobbling the Waledac botnet in February of last year, but it was considered smaller than Rustock.

"This operation, known as Operation b107, is the second high-profile takedown in Microsoft's joint effort between DCU, Microsoft Malware Protection Center and Trustworthy Computing -- known as Project MARS (Microsoft Active Response for Security) -- to disrupt botnets and begin to undo the damage the botnets have caused by helping victims regain control of their infected computers," wrote Richard Boscovich, senior attorney for the Microsoft DCU.

The international Waledac ring had been responsible for over 1.5 billion spam e-mails a day. Rustock was once held responsible for 47 percent of the world's spam, or over 30 billion e-mails a day, during its peak in December 2010. Rustock's standard operating practices to yoke computers into its network included sending spam e-mails to users concerning Microsoft lotteries that were scams, as well as offers for prescription drugs that turned out to be fakes.

With both rings, legal and technical measures were deployed to sever the connection between the main server control and the millions of infected systems. With Rustock, the team obtained a court declaration from pharmaceutical company Pfizer concerning the harmful effects of the drugs offered in the spam e-mails. According to that declaration, the drugs offered usually contained the wrong dosage amounts, incorrect active ingredients and harmful chemicals, including pesticides, floor wax and lead-based paint.

The DCU's next concern is to help unsuspecting victims of the botnet. It's doing so by working with ISPs and security organizations.

"We are also now working with Internet service providers and Community Emergency Response Teams (CERTs) around the world to help reach out to help affected computer owners clean the Rustock malware off their computers," said Boscovich.

Microsoft advises users to periodically scan their PCs for malware and remove it. The company provides some cleanup resources here.

About the Author

Chris Paoli is the site producer for and


  • Microsoft Buys Orions Systems To Enhance Vision AI Capabilities in Dynamics 365

    Microsoft announced on Tuesday that it has acquired Orions Systems with the aim of enhancing Dynamics 365 capabilities, as well as the Microsoft Power Platform.

  • Microsoft Hires Movial To Build Android OS for Microsoft Devices

    Microsoft has hired the Romanian operations of software engineering and design services company Movial to develop an Android-based operating system solution for the Microsoft Devices business segment.

  • Microsoft Ending Workflows for SharePoint 2010 Online Next Month

    Microsoft on Monday gave notice that it will be ending support this year for the "workflows" component of SharePoint 2010 Online, as well as deprecating that component for SharePoint 2013 Online.

  • Why Windows Phone Is Dead, But Not Completely Gone

    Don't call it a comeback (because that's not likely). But as Brien explains, there are three ways that today's smartphone market leaves the door open for Microsoft to bring Windows back to smartphones.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.