Security researchers reported that the Storm botnet evolved beyond spam distribution by automatically retaliating against systems that scanned infected hosts, launching sustained distributed denial-of-service attacks against the source of the probes. Higher-education networks were warned of elevated risk because routine vulnerability and malware scanning could trigger the response, and researchers said the behavior marked an unusual defensive capability for a botnet that had previously been known mainly for mass-mailing campaigns and malware propagation.
At the same time, investigators found Storm’s infrastructure being used in phishing attacks against Barclays and Halifax customers, with spam emails directing victims to fraudulent banking sites designed to steal credentials. Analysts said the campaigns suggested the botnet may have been rented or otherwise made available to other criminals, while Storm’s operators also shifted from earlier email lures toward malicious web pages as defenders improved filtering and user awareness, underscoring the botnet’s adaptability even as some observers questioned whether its momentum was fading.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
After the Barclays campaign was detected, attackers moved to a second phishing campaign targeting Halifax Bank customers using the Storm botnet. Fortinet described the incidents as the first known Storm-enabled attacks against the financial sector and said the spam appeared broadly distributed rather than based on verified customer lists.
Fortinet detected a phishing campaign targeting Barclays customers that used Storm botnet infrastructure, with emails directing victims to a fake i-Barclays site hosted on a Russia-registered domain. The messages claimed the bank was conducting account reviews to reduce fraud and sought to steal login credentials.
Coverage indicated the Storm worm may have 'blown itself out,' suggesting the botnet's earlier growth or effectiveness was waning. This marked a notable assessment that the threat's trajectory might be declining.
Security researchers said Storm operators were moving away from highly successful email lures such as fake e-cards and news alerts toward malicious web pages, reflecting adaptation to better email filtering and increased user awareness. Reports also highlighted concern that the botnet's scale could support major denial-of-service operations.
Researchers reported that the Storm worm botnet had developed an automated defensive capability that identifies systems scanning infected hosts and directs sustained distributed denial-of-service traffic at them. Ren-Isac warned higher-education institutions of elevated risk as schools resumed network scanning activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
informationweek.com
Open sourcesecureworks.com
Open sourceweb.archive.org
Open sourcedarkreading.com
Open sourcetheregister.co.uk
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.