Rustock was a major spam botnet active in the late 2000s and early 2010s, best known for generating very large volumes of junk email, including major pharmaceutical spam campaigns. It was one of the most significant global spam operations of its era and was repeatedly associated with sharp increases in worldwide spam volume. Rustock competed within the broader rogue-pharmacy spam ecosystem and has been linked in reporting to affiliates connected to SpamIt. Microsoft participated in a coordinated takedown of Rustock infrastructure in March 2011 and subsequently pursued attribution of its operators. Operationally, Rustock functioned as a high-volume spam distribution platform built on compromised systems and supporting command infrastructure. Its activity included large spam bursts capable of materially affecting global email telemetry. Reporting tied the botnet to infrastructure rented through intermediaries and to actors using aliases including Cosma2k, with additional attribution efforts naming Russian-linked individuals as possible operators or facilitators. High-confidence public reporting supports Russian nexus indicators for the operation, while some individual-level attribution remained under investigation. Rustock is primarily characterized by initial access through botnet infection at scale, persistence on compromised hosts, and sustained post-compromise use for spam delivery. Its known behavior in the supplied facts is centered on spam operations rather than ransomware, destructive activity, or espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Competing botnet associated with Cosma and used in rivalry with SPM’s Srizbi operation within the SpamIt ecosystem.
Spam botnet operation whose infrastructure was dismantled by Microsoft; the content focuses on identifying and pursuing its possible author/operators.
Botnet used to distribute large-scale junk mail, including a major pharmaceutical spam campaign that significantly increased daily spam levels.
A spam botnet that drove a major global increase in spam volume through a surge in output.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.