Storm
Storm Worm was a Windows-focused peer-to-peer malware and spam botnet active primarily from 2007 until its apparent abandonment in September 2008.
Profile source: Mallory opens in a new tabStorm
Family profile
Storm Worm was a Windows-focused peer-to-peer malware and spam botnet active primarily from 2007 until its apparent abandonment in September 2008. It propagated through social-engineering campaigns, notably malicious email messages posing as e-cards or news alerts, and later through malicious web pages. Its fast-flux infrastructure used compromised systems to host delivery content, complicating conventional infrastructure takedowns. Storm used encrypted peer-to-peer command-and-control communications, rapidly deployed variants to hinder signature-based detection, and was used to distribute spam at substantial scale. It also possessed a self-defensive capability that directed distributed denial-of-service traffic against systems that scanned infected hosts or attempted remediation. U.S. authorities alleged that Russian spam operator Peter Yuryevich Levashov controlled and operated Storm among other botnets. Storm is regarded as an early prominent public example of a peer-to-peer botnet; it is distinct from unrelated malware operations that have also used the name Storm.
Capabilities
- Ddos
- Defense Evasion
Operational record
Recent claims
MITRE ATT&CK
Storm in ATT&CK
15 distinct techniquesReporting
Research mentioning Storm
Office of Public Affairs | Russian National Convicted of Charges Relating to Kelihos Botnet | United States Department of Justice
A U.S. federal jury convicted Russian national Oleg Koshkin for operating malware crypter services that helped the Kelihos botnet evade antivirus detection and spread malicious payloads. Prosecutors said Koshkin ran sites including Crypt4U.com, Crypt4U.net, fud.bz, and fud.re, advertising tools that made malware such as botnets, RATs, keyloggers, stealers, crypto miners, and ransomware fully undetectable. Court evidence showed Kelihos operator Peter Levashov paid roughly $3,000 per month from 2014 to 2017 for custom high-volume re-crypting, while co-defendant Pavel Tsurkan pleaded guilty to aiding malware infections worldwide, including ransomware attacks. The conviction builds on the broader U.S. campaign against Kelihos, a botnet active since at least 2010 that at various points controlled 60,000 to more than 100,000 compromised Windows computers. Authorities said the botnet was used for spam, credential theft, pump-and-dump stock fraud, denial-of-service activity, and malware distribution before the FBI and partners including CrowdStrike and the Shadowserver Foundation disrupted it through a sinkholing operation and Levashov’s arrest in Spain. Investigators linked Levashov to the infrastructure through IP and account records, with reporting noting operational security mistakes such as reused credentials that helped expose him.