Skip to content

Storm

Storm Worm was a Windows-focused peer-to-peer malware and spam botnet active primarily from 2007 until its apparent abandonment in September 2008.

Profile source: Mallory opens in a new tab

Storm

Family profile

Storm Worm was a Windows-focused peer-to-peer malware and spam botnet active primarily from 2007 until its apparent abandonment in September 2008. It propagated through social-engineering campaigns, notably malicious email messages posing as e-cards or news alerts, and later through malicious web pages. Its fast-flux infrastructure used compromised systems to host delivery content, complicating conventional infrastructure takedowns. Storm used encrypted peer-to-peer command-and-control communications, rapidly deployed variants to hinder signature-based detection, and was used to distribute spam at substantial scale. It also possessed a self-defensive capability that directed distributed denial-of-service traffic against systems that scanned infected hosts or attempted remediation. U.S. authorities alleged that Russian spam operator Peter Yuryevich Levashov controlled and operated Storm among other botnets. Storm is regarded as an early prominent public example of a peer-to-peer botnet; it is distinct from unrelated malware operations that have also used the name Storm.

Capabilities

  • Ddos
  • Defense Evasion

Operational record

Recent claims

MITRE ATT&CK

Storm in ATT&CK

15 distinct techniques

Reporting

Research mentioning Storm

Jun 16
Us Department Of Justice

Office of Public Affairs | Russian National Convicted of Charges Relating to Kelihos Botnet | United States Department of Justice

A U.S. federal jury convicted Russian national Oleg Koshkin for operating malware crypter services that helped the Kelihos botnet evade antivirus detection and spread malicious payloads. Prosecutors said Koshkin ran sites including Crypt4U.com, Crypt4U.net, fud.bz, and fud.re, advertising tools that made malware such as botnets, RATs, keyloggers, stealers, crypto miners, and ransomware fully undetectable. Court evidence showed Kelihos operator Peter Levashov paid roughly $3,000 per month from 2014 to 2017 for custom high-volume re-crypting, while co-defendant Pavel Tsurkan pleaded guilty to aiding malware infections worldwide, including ransomware attacks. The conviction builds on the broader U.S. campaign against Kelihos, a botnet active since at least 2010 that at various points controlled 60,000 to more than 100,000 compromised Windows computers. Authorities said the botnet was used for spam, credential theft, pump-and-dump stock fraud, denial-of-service activity, and malware distribution before the FBI and partners including CrowdStrike and the Shadowserver Foundation disrupted it through a sinkholing operation and Levashov’s arrest in Spain. Investigators linked Levashov to the infrastructure through IP and account records, with reporting noting operational security mistakes such as reused credentials that helped expose him.

Jun 16
Bleeping Computer

US convicts Russian national behind Kelihos botnet crypting service

Apr 11
Wired Com Security

How Russian Spam King Peter Levashov Was Arrested, and His Kelihos Botnet Dismantled | WIRED

Apr 10
Cyberscoop

DOJ moves to topple Kelihos, one of the world's largest botnets - CyberScoop

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.