Skip to main content
  1. Home
  2. Computing
  3. Web
  4. Legacy Archives

Microsoft still after Rustock botnet operators

Add as a preferred source on Google

Microsoft’s stealth attack against the infamous Rustock botnet seems to have worked—the botnet has remained offline. However, Microsoft’s Digital Crimes Unit is still going after the operators, who it believes operated (and perhaps are still operating) out of Russia—and this time it’s through the press and legal process, sending notices of court orders to folks believed to be involved, and taking out 30-day ads in leading Russian newspapers in an effort to get the owners of the IP addresses that controlled Rustock to come out of the woodwork.

Microsoft Spambot infographic (Rustock) (March 2011)
Image used with permission by copyright holder

“Although history suggests that the people associated with the IP addresses and domain names connected with the Rustock botnet are unlikely to come forward in response to a court summons, we hope the defendants in this case will present themselves,” Microsoft senior attorney Richard Boscovich wrote in the company’s official blog. “If they do not, however, we will continue to pursue this case, including possibly within the Russian judicial system.”

Recommended Videos

Sending notices to the physical and email addresses associated with the IPs that controlled the botnet and taking out the ads helps Microsoft meet its legal obligations to make a “good faith” effort to contact the owners of the addresses. Microsoft’s take-down of the Rustock botnet essentially involved a coordinated take-down of its command-and-control servers, many of which were actually operating in the United States. Microsoft coordinated with security researchers, upstream providers, and law enforcement to conduct a coordinated seizure. While the takedown was conducted with court authority, the company now has to go through the due diligence to contact the owners of the IP addresses and systems involved so, if they like, they can get their day in court.

Nobody is really expecting the Rustock operators to turn up, however.

Microsoft has noted that since the takedown, the number of PCs infected with the Rustock botnet has declined substantially as more PC users update their software and remove malware from PCs. Global levels of spam also saw a significant decline in the first quarter of the year, in part due to Rustock being taken down.

Rustock’s command-and-control servers might be offline, but that doesn’t take malware off infected PCs, and there’s still a danger that, somehow, the Rustock operators might be able to re-capture their botnet of infected systems and resume their spamming. Unlike the CoreFlood botnet, there doesn’t appear to be a backdoor into Rustock that enables substitute command-and-control servers to issue shutdown or removal commands to infected machines—and do you really want someone sending commands to delete malware on your system, anyway?

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Gemini will now take notes for you in Google Meet for you, if you the minimum $20 AI tax
Yet another Google subscription just dropped for Gemini
Google Meet Take Notes for me Gemini

Google has just released a useful Gemini feature, which you can try if you are a paying member of course. The company is now bringing "Take notes for me" for Gemini, which will be available in Google Meet for Google AI Pro and Google AI Ultra subscribers, along with eligible Workspace business customers.

For personal users, the feature starts with Google AI Pro, which costs $19.99 per month in the US. In other words, Gemini can now take your Google Meet notes, provided you pay the minimum AI tax.

Read more
After iPad Pro and MacBook Pro, the iMac could be the next in line for an OLED screen upgrade
iMac with M4

The iPhone got an OLED panel in 2017, while the iPad Pro followed in 2024. Even the MacBook Pro is expected to follow later this year or early next year. But what about the iMac?

According to TrendForce, the iMac could get an OLED upgrade. There's no timeline yet, but the direction is clear. Apple wants to replace its current display technologies with OLED, raising the bar for color quality for both regular users and professionals.

Read more
This $1,299 gaming PC wants to be a Steam Machine without waiting for Valve
Valve’s Steam Machine dream is already real in MetaPC's new prebuilt
MetaPC's Steamroller is a new Steam Machine rival

Valve’s Steam Machine may be the face of SteamOS, but the platform isn't exclusive to it. A big announcement after Steam Machine's unveiling was that SteamOS would be arriving on systems outside of the new hybrid console. Now, MetaPCs is one of the first to take advantage of this by opening the preorders for the Steamroller, a new prebuilt gaming desktop that ships with SteamOS installed by default.

Though Steamroller is not trying to be a tiny console-like cube. It is a normal desktop PC with standard parts and a real upgrade path. The system costs $1,299 and is listed with a preorder date of July 3, 2026.

Read more