Skip to content

Storm

Storm, also known as the Storm worm or Storm botnet, was a major Windows-based spam botnet and peer-to-peer malware operation that emerged in 2007 and became one of the most prominent early public examples of a large-scale P2P botnet.

Profile source: Mallory opens in a new tab

Storm

Family profile

Storm, also known as the Storm worm or Storm botnet, was a major Windows-based spam botnet and peer-to-peer malware operation that emerged in 2007 and became one of the most prominent early public examples of a large-scale P2P botnet. It propagated through aggressive social-engineering campaigns, especially spammed e-card lures and other themed email messages, and used fast-flux hosting and rapidly changing variants to complicate blocking and signature-based detection. Storm is widely regarded as an important precursor to later spam and malware botnets, and some reporting describes Waledac as a successor or rewrite that reused several of its techniques.

Storm combined mass-malware distribution with resilient botnet operations. Its architecture used encrypted peer-to-peer command and control rather than relying solely on centralized infrastructure, improving survivability against takedown efforts. The botnet was used extensively for bulk spam operations and was associated with harvesting personal information and credentials from infected systems. Reporting also links its operators to broader cybercrime monetization ecosystems, including rogue pharmacy spam operations. Storm additionally demonstrated defensive and offensive botnet capabilities beyond spam: infected nodes could participate in distributed denial-of-service activity, including retaliatory attacks against systems attempting to scan for or disrupt infected hosts.

The malware primarily targeted Microsoft Windows systems. Contemporary reporting and later law-enforcement statements have associated Storm with Russian spam operator Peter Yuryevich Levashov and with actors tied to the SpamIt/Glavmed ecosystem, although attribution in historical reporting is not uniform. Storm’s bot population declined through 2008 under sustained disruption pressure, including defensive cleanup efforts and researcher interference, and the botnet is generally considered to have ceased operating in September 2008. Its significance endures because it helped establish patterns later seen in major botnets: P2P resilience, encrypted control channels, fast-flux support infrastructure, high-volume spam delivery, credential harvesting, and adaptive evasion against defenders.

Capabilities

  • Credential Theft
  • Ddos
  • Defense Evasion

Operational record

Recent claims

MITRE ATT&CK

Storm in ATT&CK

15 distinct techniques

Reporting

Research mentioning Storm

Jun 16
Us Department Of Justice

Office of Public Affairs | Russian National Convicted of Charges Relating to Kelihos Botnet | United States Department of Justice

A U.S. federal jury convicted Russian national Oleg Koshkin for operating malware crypter services that helped the Kelihos botnet evade antivirus detection and spread malicious payloads. Prosecutors said Koshkin ran sites including Crypt4U.com, Crypt4U.net, fud.bz, and fud.re, advertising tools that made malware such as botnets, RATs, keyloggers, stealers, crypto miners, and ransomware fully undetectable. Court evidence showed Kelihos operator Peter Levashov paid roughly $3,000 per month from 2014 to 2017 for custom high-volume re-crypting, while co-defendant Pavel Tsurkan pleaded guilty to aiding malware infections worldwide, including ransomware attacks. The conviction builds on the broader U.S. campaign against Kelihos, a botnet active since at least 2010 that at various points controlled 60,000 to more than 100,000 compromised Windows computers. Authorities said the botnet was used for spam, credential theft, pump-and-dump stock fraud, denial-of-service activity, and malware distribution before the FBI and partners including CrowdStrike and the Shadowserver Foundation disrupted it through a sinkholing operation and Levashov’s arrest in Spain. Investigators linked Levashov to the infrastructure through IP and account records, with reporting noting operational security mistakes such as reused credentials that helped expose him.

Jun 16
Bleeping Computer

US convicts Russian national behind Kelihos botnet crypting service

Apr 11
Wired Com Security

How Russian Spam King Peter Levashov Was Arrested, and His Kelihos Botnet Dismantled | WIRED

Apr 10
Cyberscoop

DOJ moves to topple Kelihos, one of the world's largest botnets - CyberScoop

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.