Monday, June 18, 2007

Zombies on the attack

spamnation.info is getting hit with another distributed denial of service (DDoS) attack. This is the latest in a series of attacks launched against prominent anti-spam sites. Other sites hit by earlier waves included Spamhaus, SURBL and URIBL.

The attack is much larger than the attack against spamnation.info earlier this year. I just counted more than 1200 attacking clients. As in the previous attack, the attacking botnet is believed to have been created by the Storm Worm malware (also known as Zhelatin), which is thought to be distributed and used by a Russian spam gang.

There are rumors that the Zhelatin gang are acting not as principals but as paid 'muscle' for a third party in these attacks. The Zhelatin gang build the botnets and sell time on them - for spam, for DDoS attacks, hosting and other purposes - but the actual decision to commission a DDoS is made by someone else, presumably someone whose business is being hurt by the activities of anti-spammers.