SecureWorks Reveals More on Ron Paul Spam Botnet
December 6th, 2007
SecureWorks has an interesting although technical article up about the innerworkings of Ron Paul spam:
On the weekend of October 27, 2007, the Internet was suddenly bombarded with a rash of spam emails promoting U.S. presidential candidate Ron Paul. The spam run continued until Tuesday, October 30, when it stopped as suddenly as it began. At the same time, political blogs began to light up, accusing the campaign (or at least its ardent supporters) of running a criminal botnet for political purposes. We decided to cut through the spin and take a closer look at this botnet to determine its origins and shine some light on who might be responsible.
Ars Technica broke it down a little clearer
the recent flurry of Ron Paul spam originated from a Reactor botnet controlled by a commercial spammer through a colocation facility in the US.
Researchers: Ron Paul campaign e-mails originating from spambots
The researchers analyzed header elements of the spam e-mails to trace them back to zombie systems that were infected with the Srizbi trojan, an unusual piece of malware with highly advanced features.
Posted in Ron Paul, Tech 2008 | No Comments »