Rustock operated as a stealthy Windows rootkit and modular spam bot that injected its spam component into services.exe, used encrypted HTTP POST traffic for command-and-control, and protected those exchanges with RC4 after a key-exchange phase. Reverse-engineering showed the malware could profile infected hosts, kill competing malware, download spam templates and recipient lists, retrieve mail-server targets and SMTP failure strings, and update itself while remaining difficult to detect. Public sample collections and analysis links document multiple variants including Rustock.C, Rustock.E, Rustock.I, Rustock.J, and related builds observed across several years.
Investigators later tied parts of Rustock’s infrastructure to financially motivated spam operations, including counterfeit-drug promotions linked to the SpamIt and Rx-Promotion affiliate programs and pump-and-dump stock campaigns. After Microsoft seized dozens of U.S.-hosted command-and-control servers, reporting traced hosting payments to a WebMoney account associated with a person identified as Vladimir Shergin in Saint Petersburg, though definitive attribution remained unresolved. Separate monitoring of the botnet’s spam runs showed how operators could profit by promoting thinly traded penny stocks, with one observed campaign driving heavy trading and a sharp price increase after millions of spam emails were sent.

Pull IOCs and campaign context straight into your stack.
16 events from the most recent confirmed update back to the earliest known activity.
The rogue pharmacy affiliate program SpamIt shut down in September 2010 after its alleged leader came under scrutiny from Russian authorities. Later Rustock reporting tied a WebMoney account associated with suspected Rustock infrastructure to top SpamIt affiliates.
Records from the rogue pharmacy program Rx-Promotion showed that Cosma2k, Bird, and Adv1 collectively earned about $200,000 in commissions in 2010. The same accounts were registered there using the same ICQ account, reinforcing links among the affiliates.
SpamIt records showed that the affiliate account Bird generated more than $130,000 in pharmacy sales in January 2010, exceeding the next most successful affiliate at about $86,000. Later reporting linked Bird to the same identifiers associated with suspected Rustock operators.
VirusTotal first saw the Rustock 23 sample on November 7, 2009. The sample is identified by MD5 1A713083A0BC21BE19F1EC496DF4E651.
VirusTotal first saw the Rustock.I sample on October 7, 2009. The sample is identified by MD5 4A5E58D6351C342F3EDC145F6F4EEAFE.
A sample labeled Rustock 23 was timestamped on October 1, 2009. The sample is listed with MD5 1A713083A0BC21BE19F1EC496DF4E651.
A Rustock.I sample was timestamped on September 15, 2009. The sample is listed with MD5 4A5E58D6351C342F3EDC145F6F4EEAFE.
VirusTotal first saw the Rustock.NFE sample on March 20, 2009. This sample is identified by MD5 8E4994543ADBC2BA2103C6F801898356.
A Rustock.NFE sample was timestamped on March 2, 2009. The sample is listed with MD5 8E4994543ADBC2BA2103C6F801898356.
VirusTotal first saw a Rustock.J sample on August 22, 2008. The sample is identified by MD5 76101675D9CF5BA5238CAE9D5FAC8881.
A Rustock.E sample was timestamped on September 26, 2007. The sample is listed with MD5 04BA40662923BE168CA4DC2DA924A0D0.
VirusTotal first saw the Rustock.C sample on January 22, 2007. The sample is identified by MD5 FDAFB3A14338B2B612C4E5C4F94B3677.
A Rustock.C sample with MD5 FDAFB3A14338B2B612C4E5C4F94B3677 was timestamped on January 19, 2007. This is the same lzx32.sys variant later analyzed in the USENIX case study.
After the takedown, investigators found that about one-third of the Rustock control servers had been rented through an Eastern European reseller and paid for via WebMoney purse Z166284889296. A former law enforcement officer said the attested account was in the name Vladimir Shergin, and the same payment identifier was linked to top SpamIt and Rx-Promotion affiliates.
Microsoft disrupted the Rustock botnet by obtaining a court order and seizing dozens of command-and-control servers hosted by U.S.-based providers. The servers had been coordinating hundreds of thousands of infected PCs and distributing updates and spam instructions.
Ken Chiang and Levi Lloyd published a reverse-engineering case study of Rustock that detailed its rootkit loader, spam-module extraction, RC4-protected HTTP C2, and injection into services.exe. The work also showed how decrypted sessions revealed commands for killing competing malware, profiling hosts, and retrieving spam infrastructure data.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
secureworks.com
Open sourcecontagiodump.blogspot.com
Open sourcekrebsonsecurity.com
Open sourceusenix.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.