Waledac is a Windows spam botnet malware family active in the late 2000s and widely regarded as a successor or rewrite of Storm. It operated as a large-scale email-distribution platform and botnet, using peer-to-peer elements, encryption, and resilient command-and-control techniques including fast-flux-style infrastructure. Waledac was used to send massive volumes of spam promoting rogue online pharmacies, counterfeit goods, employment scams, penny-stock schemes, phishing lures, and related criminal campaigns. It has also been described as capable of stealing data and harvesting personal information and credentials from infected systems, including email addresses, usernames, logins, and passwords.
Waledac infections were observed being distributed through email-driven lure campaigns, including e-card themed spam, and it was also redeployed via other malware ecosystems. Reporting linked it to delivery by Conficker/Kido and to later redeployment through Virut. The malware’s operators rented botnet capacity and spam services to other criminals, reflecting its role as part of the broader spam affiliate and rogue-pharmacy ecosystem. Multiple reports and law-enforcement statements associated Waledac with Russian cybercriminal Pyotr Levashov, also known as Severa, and with actors tied to the SpamIt/Glavmed rogue-pharmacy network.
The botnet reached substantial scale, with estimates ranging from tens of thousands to hundreds of thousands of infected computers and daily spam capacity in the billions of messages. Microsoft disrupted Waledac in 2010 through Operation b49, combining civil legal action against command-and-control domains with technical countermeasures against remaining peer-to-peer control channels. Although that action significantly impaired the botnet, it did not by itself remediate infected hosts, and Waledac remained notable as one of the defining spam botnets of its era.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Pyotr Levashov, also known as Severa, operated rogue antivirus partnerkas ... in addition to spreading the infamous Waledac and Kelihos botnets.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The Department of Justice said that Levashov “controlled and operated multiple botnets, including the Storm, Waledac, and Kelihos botnets to harvest personal information and means of identification (including email addresses, usernames and logins, and passwords) from infected computers.”
This episode tells the stories of some of the worlds biggest spamming botnets. We’ll talk about the botnets Rustock, Waledac, and Cutwail.
The members of SpamIt are allegedly the group behind the Storm, Waledec and potentially Conficker botnets, responsible for email distribution and fast-flux hosting of the spam websites
Almost all the blocked domain names were registered in China.
Levashov controlled and operated multiple botnets, including the Storm, Waledac and Kelihos botnets
This should stop thousands of bots -- in this case, between 30,000 and 90,000 compromised Windows PCs -- from receiving instructions to send out spam emails, at least for a while.
Junk email campaigns touting employment or “money mule” scams cost $300 per million, and phishing emails could be blasted out through Severa’s botnet for the bargain price of $500 per million.
Over a 12-hour period, Iksmas connected to its control centers around the globe a number of times and received commands to send out spam mailings.
Control: HTTP with encryption, multiple TCP ports ... Control: HTTP on TCP port 80 ... Control: HTTP on high ports ... Control: AES and RSA-encrypted, encapsulated in HTTP
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A spam-focused botnet highlighted as one of the major spamming botnets covered in the episode.
Viikon haittaohjelmakatsauksessa on Waledac.
Malware 2009 Conficker Koobface Waledac
"...when we started back, way back from Waledac and all those old old malware operations..."
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.