Rustock was a Windows kernel-mode rootkit and spam botnet active primarily from the mid-2000s through its disruption in 2011. It installed a malicious driver to obtain boot-time persistence and conceal its components, including by hiding system artifacts and manipulating networking-related kernel drivers. The rootkit extracted and injected an embedded spam module into a Windows service process, enabling compromised hosts to operate as high-volume spam senders. Rustock used encrypted HTTP-based command-and-control communications, host profiling, modular updates, and commands to remove competing malware. Its spam operations supported fraudulent campaigns including rogue-pharmacy advertising and pump-and-dump stock promotions. The botnet was among the largest global spam sources of its period, with command infrastructure disrupted through coordinated legal and technical action in 2011. Public reporting linked aspects of its monetization to Russian-language criminal spam affiliate ecosystems, but definitive attribution of Rustock's operators remained unresolved.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Earlier in my Pharma Wars series, I detailed the activities of Cosma — the top SpamIt affiliate who appears to have been responsible for a botnet that competed directly with SPM’s – Rustock.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
No surprise, as it turns out the motive is spam. Using a sandnet, I injected myself into the botnet, able to capture (and blackhole) a small portion of the spam being sent through the system.
This episode tells the stories of some of the worlds biggest spamming botnets. We’ll talk about the botnets Rustock, Waledac, and Cutwail.
This technique is known as a “drive-by download”; when a user views the infected site, malicious code will be installed to the victim machine without the user’s knowledge or consent.
The registry key HKLM\system\CurrentControlSet\services\pe386 used to start the malware disappears from the registry as soon as the malware is loaded... the rootkit component entry function... [uses] the registry path pointing to the registry key that loaded the malware driver file into the operating system.
This notify routine creates at most two threads to inject the spam component into the services.exe process... It was previously mentioned that the spam module is injected into the services.exe process, this is another step taken by the malware to thwart detection.
The registry key HKLM\system\CurrentControlSet\services\pe386 used to start the malware disappears from the registry as soon as the malware is loaded... the rootkit component entry function... [uses] the registry path pointing to the registry key that loaded the malware driver file into the operating system.
Rustock, TDSS/TDL-1, and ZeroAccess are described as providing process, file, registry, and network hiding functionality in kernel mode.
This notify routine creates at most two threads to inject the spam component into the services.exe process... It was previously mentioned that the spam module is injected into the services.exe process, this is another step taken by the malware to thwart detection.
Deletes all sub-keys in the hive: HKLM\system\CurrentControlSet\Enum\Root\Legacy_lzx32.sys
Next, the client sends information about itself to the server including bandwidth, OS version, SMTP availability (if outbound TCP/25 is allowed), if it is a virtual machine...
Next, the client sends information about itself to the server including bandwidth, OS version, SMTP availability (if outbound TCP/25 is allowed), if it is a virtual machine, and if it is blacklisted on a DNS blacklist.
Microsoft crippled Rustock by convincing a court to let it seize dozens of Rustock control servers... the servers only were used to coordinate the activities of hundreds of thousands of PCs infected with Rustock, periodically sending them program updates and new spamming instructions.
Both phases are initiated by the client in the form of HTTP POSTs... The HTTP POST from the client contains a 96-byte encrypted payload and is sent to the login.php page on the server... The instruction phase... consists of a variable number of HTTP POSTs from the client and corresponding responses from the server.
McColo was one of the leading players in the so-called "bulletproof hosting" market — ISPs that will allow servers to remain online regardless of complaints.
the servers only were used to coordinate the activities of hundreds of thousands of PCs infected with Rustock, periodically sending them program updates and new spamming instructions.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A major spam botnet used to send large volumes of unsolicited email, including pharmacy spam, and discussed as one of the world's biggest spamming botnets.
Named as one of several major botnets with control servers hosted by McColo.
Rustock is described as a trojan-operated botnet used to send massive volumes of spam, specifically pump-and-dump stock spam intended to manipulate penny stock prices for profit.
Malware 2006 Rustock ZLOB Clickbot Stration
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.