Storm is a historically significant malware family best known as the Storm worm/botnet active in 2007–2008. The content describes it as a large spam-oriented botnet/worm that propagated through social-engineering lures, especially fake e-cards and fake news alerts, and later also through malicious web pages. It used encrypted peer-to-peer command and control and rapidly deployed new variants to evade antivirus signatures. Storm also used fast-flux hosting for malicious sites and was associated with large-scale spam distribution. Reported capabilities include harvesting personal information and credentials from infected systems, including email addresses, usernames/logins, and passwords. The botnet was also configured for denial-of-service activity; researchers reported that Storm could launch retaliatory DDoS attacks against systems scanning infected hosts, and broader reporting noted DDoS capability beyond spam operations. The content links Storm to actors associated with SpamIt/Glavmed and repeatedly associates it with Peter Yuryevich Levashov (aka Severa), with U.S. DOJ statements alleging he controlled and operated Storm as well as Waledac and Kelihos. Storm is also described as a precursor or technical ancestor to Waledac, which was characterized as a likely rewrite reusing techniques such as P2P, encryption, e-card lures, DDoS capability, and double fast-flux hosting. According to the content, Storm dominated for roughly two years and the botnet effectively died on 2008-09-18 after sustained disruption by researchers and reductions from Microsoft’s Malicious Software Removal Tool. The same content set also contains a separate 2026 mention of a new infostealer called "Storm," but another report explicitly states an observed 2026 stealer did not technically match any documented family including Storm; therefore the high-confidence, widely recognized malware name in this corpus is the 2007–2008 Storm worm/botnet.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The Department of Justice said that Levashov “controlled and operated multiple botnets, including the Storm, Waledac, and Kelihos botnets to harvest personal information and means of identification (including email addresses, usernames and logins, and passwords) from infected computers.”
Its main brand is the notorious ‘Canadian Pharmacy’, which is all too familiar to everyone through massive email spam campaigns that seem never to end.
The members of SpamIt are allegedly the group behind the Storm, Waledec and potentially Conficker botnets, responsible for email distribution and fast-flux hosting of the spam websites
Feed in a Google Refresh Token and a geographically matched SOCKS5 proxy, and the panel silently restores the victim's authenticated session.
But because of the P2P functionality in the Storm code, it was never fully possible to take over the entire botnet at once. ... Waledac appears to be a from-scratch rewrite of Storm. Although the code is completely new, it uses many of the old tricks (P2P, encryption, e-card links, spam, DDoS, double fast-flux hosting)
“For over two decades, Peter Levashov operated botnets which enabled him to harvest personal information from infected computers, disseminate spam, and distribute malware used to facilitate multiple scams,” said Assistant Attorney General Brian Benczkowski in a statement.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a comparison family that did not technically match the observed sample.
A worm-associated botnet used for large-scale spam and DDoS activity. The content describes it as capable of launching distributed denial-of-service attacks against systems scanning for vulnerabilities or malware, and notes its operators also shifted from email lures to malicious web pages.
Storm is an infostealer that harvests browser credentials, session cookies, crypto wallets, documents, messaging app session data, system information, and screenshots. It avoids local browser credential decryption by exfiltrating encrypted browser data to attacker-controlled infrastructure for server-side decryption, and supports automated session restoration using stolen tokens and proxies.
Malware 2007 Storm ZeuS Black Energy 1
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.