A coordinated effort by FireEye, Spamhaus, CERT-GIB, and independent researchers disrupted Grum, one of the world’s largest spam botnets, by taking down its command-and-control infrastructure across multiple countries. The operation first removed a Dutch server, then shut down a Panamanian server that permanently disabled one of Grum’s two operational segments. After the botnet’s operators shifted control to six new secondary servers in Ukraine while retaining a primary server in Russia, defenders shared intelligence with providers and partners to force those systems offline as well, including null-routing the Russian node through its upstream network.

Pull IOCs and campaign context straight into your stack.
10 events from the most recent confirmed update back to the earliest known activity.
On August 20, Krebs on Security published a deeper look inside the Grum botnet. The report added technical and operational context to the already documented takedown.
On August 16, Spamhaus published a retrospective describing the collapse of Grum and the emergence of Festi as a successor spam botnet threat. This marked a broader shift in the spam botnet landscape after Grum's disruption.
By July 24, reporting indicated that Grum's operators had tried to restore the botnet after the takedown but were unsuccessful. This showed the disruption had held despite follow-on recovery attempts.
FireEye published details of the coordinated three-day operation and said the world's third-largest spam botnet had been effectively knocked down. The report highlighted the significance of disrupting infrastructure in Russia and Ukraine.
Following the takedown, Spamhaus data showed Grum-related spam-sending IPs falling from roughly 120,000 per day to 21,505. The figures reflected actively spamming bots rather than the botnet's full infected population.
By July 18 at 11:00 AM PST, all six Ukrainian servers and the original Russian primary server were offline, effectively knocking down the Grum botnet. The Russian server was reportedly null-routed by its upstream provider.
During the takedown effort, FireEye provided intelligence on the replacement infrastructure to Spamhaus, CERT-GIB, and researcher Nova7. This coordination supported action against the newly identified servers.
After losing infrastructure, the botnet's operators attempted to reconstitute command-and-control by standing up six new secondary servers in Ukraine while retaining a Russian primary server. The move was a direct attempt to keep the botnet operational after the Panama disruption.
On July 17, defenders succeeded in taking down a Grum command server in Panama. FireEye said this permanently killed one of the botnet's two operational segments.
A Dutch command-and-control server used by the Grum spam botnet was taken offline as part of the early phase of a coordinated disruption effort. This preceded the final takedown and forced the operators to rely on remaining infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
krebsonsecurity.com
Open sourcespamhaus.org
Open sourcetheverge.com
Open sourcehelpnetsecurity.com
Open sourcekrebsonsecurity.com
Open sourcefireeye.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.