Storm
Storm, also known as the Storm worm or Storm botnet, was a major Windows-based spam botnet and peer-to-peer malware operation that emerged in 2007 and became one of the most prominent early public examples of a large-scale P2P botnet.
Profile source: Mallory opens in a new tabStorm
Family profile
Storm, also known as the Storm worm or Storm botnet, was a major Windows-based spam botnet and peer-to-peer malware operation that emerged in 2007 and became one of the most prominent early public examples of a large-scale P2P botnet. It propagated through aggressive social-engineering campaigns, especially spammed e-card lures and other themed email messages, and used fast-flux hosting and rapidly changing variants to complicate blocking and signature-based detection. Storm is widely regarded as an important precursor to later spam and malware botnets, and some reporting describes Waledac as a successor or rewrite that reused several of its techniques.
Storm combined mass-malware distribution with resilient botnet operations. Its architecture used encrypted peer-to-peer command and control rather than relying solely on centralized infrastructure, improving survivability against takedown efforts. The botnet was used extensively for bulk spam operations and was associated with harvesting personal information and credentials from infected systems. Reporting also links its operators to broader cybercrime monetization ecosystems, including rogue pharmacy spam operations. Storm additionally demonstrated defensive and offensive botnet capabilities beyond spam: infected nodes could participate in distributed denial-of-service activity, including retaliatory attacks against systems attempting to scan for or disrupt infected hosts.
The malware primarily targeted Microsoft Windows systems. Contemporary reporting and later law-enforcement statements have associated Storm with Russian spam operator Peter Yuryevich Levashov and with actors tied to the SpamIt/Glavmed ecosystem, although attribution in historical reporting is not uniform. Storm’s bot population declined through 2008 under sustained disruption pressure, including defensive cleanup efforts and researcher interference, and the botnet is generally considered to have ceased operating in September 2008. Its significance endures because it helped establish patterns later seen in major botnets: P2P resilience, encrypted control channels, fast-flux support infrastructure, high-volume spam delivery, credential harvesting, and adaptive evasion against defenders.
Capabilities
- Credential Theft
- Ddos
- Defense Evasion
Operational record
Recent claims
MITRE ATT&CK
Storm in ATT&CK
15 distinct techniquesReporting
Research mentioning Storm
Office of Public Affairs | Russian National Convicted of Charges Relating to Kelihos Botnet | United States Department of Justice
A U.S. federal jury convicted Russian national Oleg Koshkin for operating malware crypter services that helped the Kelihos botnet evade antivirus detection and spread malicious payloads. Prosecutors said Koshkin ran sites including Crypt4U.com, Crypt4U.net, fud.bz, and fud.re, advertising tools that made malware such as botnets, RATs, keyloggers, stealers, crypto miners, and ransomware fully undetectable. Court evidence showed Kelihos operator Peter Levashov paid roughly $3,000 per month from 2014 to 2017 for custom high-volume re-crypting, while co-defendant Pavel Tsurkan pleaded guilty to aiding malware infections worldwide, including ransomware attacks. The conviction builds on the broader U.S. campaign against Kelihos, a botnet active since at least 2010 that at various points controlled 60,000 to more than 100,000 compromised Windows computers. Authorities said the botnet was used for spam, credential theft, pump-and-dump stock fraud, denial-of-service activity, and malware distribution before the FBI and partners including CrowdStrike and the Shadowserver Foundation disrupted it through a sinkholing operation and Levashov’s arrest in Spain. Investigators linked Levashov to the infrastructure through IP and account records, with reporting noting operational security mistakes such as reused credentials that helped expose him.