Mega-D, also known as Ozdok, was a major spam botnet that at its peak was responsible for a large share of global unsolicited email, with estimates placing it at roughly one-third of worldwide spam. It operated as a zombie network of up to approximately 500,000 infected Windows PCs and was used to distribute massive volumes of junk mail, including campaigns tied to rogue online pharmacy and counterfeit-goods affiliate programs. U.S. authorities alleged that Oleg Nikolaenko, known online as Docent, operated the botnet and later reported that he pleaded guilty to running Mega-D.
Mega-D’s core function was centralized botnet control for spam operations. Its command infrastructure coordinated infected hosts and delivered spam instructions and templates at very high scale, with authorities stating the botnet was capable of sending more than 10 billion spam messages per day. Researchers later reverse engineered Mega-D’s proprietary protocol and documented a design flaw that allowed unauthorized retrieval of spam templates, enabling defenders to study campaigns and improve filtering before some messages were sent.
The botnet’s infrastructure was resilient and recovered after disruption efforts. In October 2008, U.S. regulators cooperated with private-sector partners to identify the operators and freeze assets associated with the operation. In November 2009, a coordinated takedown involving security researchers, internet service providers, registrars, and nonprofit defenders disrupted Mega-D’s command-and-control structure and temporarily halted its spam output. The interruption was short-lived, and the botnet regained activity within weeks, again becoming a significant global spam source.
Mega-D was part of the broader criminal spam ecosystem and was associated with bulletproof hosting and other major spam botnets. Its master servers were reported to have been hosted at McColo alongside infrastructure used by other prominent botnets. Mega-D is best characterized as a large-scale spam botnet used for centralized control of compromised systems and monetized through affiliate-driven spam campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
That was the nickname used by Oleg Nikolaenko, a 24-year-old Russian man arrested in Las Vegas in Nov. 2010 charged with operating the Mega-D botnet.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The U.S. Justice Department alleges that Nikolaenko, using the online nickname “Docent” earned hundreds of thousands of dollars using his “Mega-D” botnet, which authorities say infected more than half a million PCs and could send over 10 billion spam messages a day.
The U.S. Justice Department alleges that Nikolaenko, using the online nickname “Docent” earned hundreds of thousands of dollars using his “Mega-D” botnet, which authorities say infected more than half a million PCs and could send over 10 billion spam messages a day.
According to Joe Stewart, director of malware research for SecureWorks, the Mega-D, Srizbi, Pushdo, Rustock and Warezov botnets all hosted their master servers at McColo; numerous complaints had been made but McColo simply moved offending servers and sites to different subnets.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet operated by Oleg Nikolaenko, mentioned in connection with spam-related criminal activity.
A large spam botnet allegedly operated by Oleg Nikolaenko that infected more than 500,000 PCs and was capable of sending over 10 billion spam messages per day.
Mentioned as an example of a successful botnet requiring only limited operator resources.
A large spam botnet used to send massive volumes of unsolicited email worldwide, at one point accounting for 32% of global spam and operating through a zombie network of up to 500,000 infected computers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.