Polish security authorities, CERT Polska, Spamhaus, home.pl, Austrian CERT, and Group-IB collaborated to disrupt the Virut botnet by seizing or suspending command-and-control domains and redirecting traffic to sinkholes. The action targeted 23 .pl domains and additional infrastructure in .ru, cutting off a major portion of the malware’s control network. Virut, active since 2006, is a file-infecting worm and botnet that spreads through removable drives, network shares, and infected files, and at its peak was linked to hundreds of thousands of compromised systems.
The disruption hit a malware platform that had been used for pay-per-install operations, including delivery of ZeuS and Kehlios, and had also been tied to broader criminal activity such as the re-emergence of the Waledac spam botnet. Researchers warned that the impact might be temporary because parts of Virut’s infrastructure remained outside Polish jurisdiction and the malware used a domain generation algorithm (DGA) that could allow operators to re-establish command and control if they registered newly generated domains. At the time, unresolved infrastructure in the .at namespace remained a notable holdout.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Symantec published analysis describing Virut's domain generation algorithm, noting infected systems could generate up to 10,000 possible domains per day if hard-coded controllers were unreachable.
In December 2012, Spamhaus had Virut command-and-control domains in the .pl ccTLD suspended through various Polish registrars.
CERT Polska reported that more than 890,000 unique IP addresses in Poland were infected by Virut in 2012, underscoring the scale of the threat.
Microsoft conducted a high-profile takedown against the Waledac spam botnet, which later reporting said Virut had been used to redeploy.
Team Furry published research in 2007 linking Virut-related infrastructure to individuals it believed created and operated the botnet, including handles XMAX and Adx.
Virut was first detected in 2006 and went on to become a significant botnet and file-infecting malware threat.
Using evidence and intelligence from Spamhaus, Group-IB's CERT-GIB shut down all Virut domains in the .ru ccTLD within a few hours.
In the days before the report, Spamhaus worked with CERT.pl and home.pl to suspend and sinkhole all Virut command-and-control domains in the .pl ccTLD.
After the December 2012 disruption, Virut operators quickly moved malicious domains to registrar home.pl in an attempt to restore command-and-control.
Polish authorities and NASK began taking control of 23 .pl domains used to operate Virut and redirected their traffic to CERT Polska's sinkhole infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
symantec.com
Open sourcesymantec.com
Open sourcespamhaus.org
Open sourcekrebsonsecurity.com
Open sourcecert.pl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.