Festi, also known as Spamnost and referred to in one source as Topol-Mailer, is a Windows rootkit-based botnet primarily used for large-scale spam distribution and distributed denial-of-service attacks. Antivirus researchers first observed it in autumn 2009. Reporting cited in the content describes it as one of the world’s largest and most active spam botnets, with estimates of roughly 25,000 infected machines early on and later activity in 2011–2012 reaching about 250,000 to nearly 300,000 spam-sending IP addresses. Early estimates said it could send about 2.5 billion spam emails per day.
Festi was distributed via a pay-per-install scheme. Its loader downloads and installs a bot implemented as a kernel-mode driver and adds itself to the list of drivers that start with the operating system. The malware uses an encrypted loader and a modular plug-in architecture. After startup, it periodically contacts its command-and-control infrastructure to receive configuration, modules, and tasks. The content states that only the component responsible for command-center communication and module loading is stored on disk, while modules themselves are not saved to disk, complicating detection.
Documented modules include BotSpam.dll for spam sending and BotDoS.dll for DDoS attacks. Reported additional modules include BotSocks.dll, which implements a SOCKS server over TCP and UDP; BotRemote.dll for remote viewing and control of the infected system; BotSearch.dll for searching disks and local area networks connected to the victim; and BotGrabber.dll, described as a browser credential-grabbing module. The DDoS functionality reportedly supports TCP, UDP, DNS, HTTP, HTTPS, and random-protocol packet flooding.
The malware uses a custom client-server protocol with encoded data for command-and-control communications and includes multiple anti-analysis and stealth features. Reported behaviors include disabling the system firewall, hiding its kernel-mode driver and registry keys, checking for virtual machines and debuggers, examining the KdDebuggerEnabled kernel variable, clearing hardware breakpoint registers dr0 through dr3, intercepting filesystem requests around \SystemRoot to hide its driver on disk, and hiding its service registry key under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services by hooking ZwEnumerateKey via SSDT modification.
The content associates Festi with Russian hacker Igor Artimovich, also known as Engel. Group-IB and other cited reporting linked Artimovich to use of the botnet in the DDoS attack against Assist, a payment processor competing with ChronoPay for Aeroflot’s payment-processing business. The same reporting also ties Festi to spam and DDoS activity in the rogue pharmacy underground, including attacks against competing affiliate programs. High-confidence indicators and artifacts directly mentioned in the content include the aliases Spamnost and Topol-Mailer, the module names BotSpam.dll, BotDoS.dll, BotSocks.dll, BotRemote.dll, BotSearch.dll, and BotGrabber.dll, and the email address support@id-search.org referenced in reporting about Artimovich.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Group-IB’s evidence suggested Artimovich had used a botnet he called Topol-Mailer to launch the attacks, but Topol-Mailer is more commonly known as Festi, one of the world’s largest and most active spam botnets. As detailed by researchers at NOD32 Antivirus makers ESET, Festi was built not just for spam, but to serve as a very powerful tool for launching distributed denial of service (DDoS) attacks.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Topol-Mailer is more commonly known as Festi, one of the world’s largest and most active spam botnets.
The loader downloads and sets up a bot which represents a kernel-mode driver which adds itself in the list of the drivers which are launching together with an operating system.
For preventing of detection by antiviruses the loader extends ciphered that complicates signature based detection.
The bot checks, whether it is launched under the virtual machine, in case of positive result of the check, it stops the activities.
In case of installation the bot switches off a system firewall, hides the kernel-mode driver and the keys of the system registry necessary for loading and operation, protects itself and registry keys from deleting.
Festi also hides a registry key corresponding to the registered kernel-mode driver using a similar method.
the module implementing search on a disk of the remote computer and in a local area network (BotSearch.dll) to which the remote computer is connected
After starting the bot periodically asks the command center for receiving a configuration, loading of the modules and the jobs necessary for execution.
Their list includes the module for socks-server implementation (BotSocks.dll) with the TCP and UDP protocols.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular rootkit and bot with plug-in architecture, distributed via PPI, that installs a kernel-mode driver, downloads plug-ins from a C2 server, uses anti-debugging techniques, hides its driver on disk by hooking the filesystem driver, and conceals its registry key by hooking ZwEnumerateKey via SSDT modification.
Named as an example rootkit to be explored in the series.
Windows-based rootkit and botnet primarily used for large-scale spam distribution and distributed denial-of-service attacks. It uses a loader and modular architecture, includes spam and DDoS modules, can disable the system firewall, hide its driver and registry keys, evade antivirus and debugging, and communicate with command-and-control servers using its own encoded protocol.
A spam botnet that rapidly expanded in mid-2012 and generated very large volumes of spam, at one point involving nearly 300,000 infected IP addresses in a 24-hour period.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.