Srizbi was a large Windows spam botnet malware family active primarily from 2007 through 2008 and widely associated with the Reactor Mailer spam platform. It infected Microsoft Windows systems at scale and turned them into remotely managed spambots used to distribute massive volumes of unsolicited email, including pharmaceutical spam, fake-product campaigns, and other commercial spam operations. At its peak, Srizbi was assessed as one of the largest spam botnets on the Internet and was at times credited with a very large share of global spam output.
Srizbi was distributed through web-based exploit infrastructure, including MPack and n404, embedded in hacked or malicious websites. In addition to exploit-kit delivery, it was also used in spam-driven self-propagation campaigns that lured users to malicious links. Once installed, infected hosts contacted command infrastructure to retrieve spam templates, recipient data, and operational configuration. The botnet used segmented and redundant controller infrastructure, and later recovery efforts reportedly incorporated domain-generation logic to help operators reestablish control after takedowns.
The malware is notable for stealth and low-level system manipulation. Reporting described Srizbi as executing in kernel mode and using rootkit techniques to evade detection, including hiding files through NTFS-related tampering and concealing network activity by attaching to network stack components. Srizbi has also been observed using process-injection-related APIs, a behavior shared with several other major malware families of the period.
Operationally, Srizbi functioned as the mailing component of Reactor Mailer, a spamware service that provided web-based management for spam customers. Reactor Mailer supported multi-account access and campaign management, indicating that Srizbi capacity was rented or sold as a service to third-party spammers. Srizbi was linked to the underground alias SPM and to the broader rogue-pharmacy spam ecosystem, including SpamIt. Researchers also noted similarities between Srizbi and Rustock code, suggesting either shared development lineage or substantial borrowing.
Srizbi was implicated in several high-volume spam campaigns, including a notable 2007 political spam run promoting Ron Paul, though that activity appeared to be a rented use of an existing commercial spam botnet rather than a bespoke political botnet. The botnet was heavily disrupted by the 2008 takedown of hosting provider McColo, which hosted critical command infrastructure for Srizbi and other major spam botnets. That disruption caused a sharp temporary decline in global spam and significantly impaired Srizbi, although operators attempted to restore control through new infrastructure afterward.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
On the weekend of October 27, 2007, the Internet was suddenly bombarded with a rash of spam emails promoting U.S. presidential candidate Ron Paul.
Analysis of recently compromised machines indicated that Srizbi is being spread by the n404 web exploit kit, through the malicious site msiesettings.com.
Srizbi burst onto the malware scene in early 2007, infecting hundreds of thousands of Microsoft Windows computers via exploit kits stitched into hacked and malicious Web sites.
Google rented his crime machine to members of SpamIt, an organization that paid spammers to promote rogue Internet pharmacy sites... SpamIt members could rent access to the collection of hacked machines via... 'Reactor Mailer.'
By monitoring and correlating network flows, the command center was soon tracked to a server at a co-location facility located in the U.S.
McColo was one of the leading players in the so-called "bulletproof hosting" market — ISPs that will allow servers to remain online regardless of complaints.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of several major botnets with control servers hosted by McColo.
Spam botnet used to send large volumes of junk email, including pharmacy spam, and operated via infrastructure later disrupted in the McColo takedown.
Srizbi is referenced as one of several spam botnets involved in prior takedown efforts.
Named as a spam botnet involved in prior takedown efforts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.