Skip to content

Storm

Storm is a historically significant malware family best known as the Storm worm/botnet active in 2007–2008.

Profile source: Mallory opens in a new tab

Storm

Family profile

Storm is a historically significant malware family best known as the Storm worm/botnet active in 2007–2008. The content describes it as a large spam-oriented botnet/worm that propagated through social-engineering lures, especially fake e-cards and fake news alerts, and later also through malicious web pages. It used encrypted peer-to-peer command and control and rapidly deployed new variants to evade antivirus signatures. Storm also used fast-flux hosting for malicious sites and was associated with large-scale spam distribution. Reported capabilities include harvesting personal information and credentials from infected systems, including email addresses, usernames/logins, and passwords. The botnet was also configured for denial-of-service activity; researchers reported that Storm could launch retaliatory DDoS attacks against systems scanning infected hosts, and broader reporting noted DDoS capability beyond spam operations. The content links Storm to actors associated with SpamIt/Glavmed and repeatedly associates it with Peter Yuryevich Levashov (aka Severa), with U.S. DOJ statements alleging he controlled and operated Storm as well as Waledac and Kelihos. Storm is also described as a precursor or technical ancestor to Waledac, which was characterized as a likely rewrite reusing techniques such as P2P, encryption, e-card lures, DDoS capability, and double fast-flux hosting. According to the content, Storm dominated for roughly two years and the botnet effectively died on 2008-09-18 after sustained disruption by researchers and reductions from Microsoft’s Malicious Software Removal Tool. The same content set also contains a separate 2026 mention of a new infostealer called "Storm," but another report explicitly states an observed 2026 stealer did not technically match any documented family including Storm; therefore the high-confidence, widely recognized malware name in this corpus is the 2007–2008 Storm worm/botnet.

Operational record

Recent claims

MITRE ATT&CK

Storm in ATT&CK

15 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.