Researchers identified Trojan.Srizbi as a highly sophisticated Windows kernel-mode spam bot and rootkit that spread through drive-by web attacks using injected malicious IFRAMEs on legitimate sites, which redirected victims to exploit kits including MPack and n404. Once installed, Srizbi loaded a kernel driver, hid files and registry entries, bypassed security hooks, and used a private TCP/IP stack with low-level NDIS hooks to communicate directly with HTTP-based command-and-control servers from ring 0, helping it evade personal firewalls and maintain resilient spam operations.
Further investigation tied Srizbi to large-scale spam activity, including the late-October "Ron Paul" email campaign, which analysts concluded was sent by an existing botnet rather than a purpose-built political network. Distinctive email header fingerprints, thousands of sending IPs, and seized controller software linked the operation to the Reactor Mailer spam platform run by a spammer known as spm, with the campaign attributed to an account named nenastnyj; researchers also found that Srizbi could remove competing rootkits such as Rustock.B and Pandex, and published detection guidance including Snort signatures for its network traffic.

Pull IOCs and campaign context straight into your stack.
10 events from the most recent confirmed update back to the earliest known activity.
A spam campaign promoting Ron Paul ran from October 27 to October 30, 2007. Researchers later concluded it was sent through an existing Srizbi botnet that also distributed ordinary spam such as pharmaceuticals and fake watches.
In June 2007, attackers injected malicious IFRAMEs into legitimate Italian and Russian websites, redirecting visitors to an MPack exploit kit. That infrastructure downloaded several trojans, including Srizbi, from 81.95.146.150.
Analysts began examining Srizbi's kernel-mode driver in June 2007 as the malware emerged in the wild. Their work found no signs of user-mode injection, indicating the malware operated entirely in ring 0.
Researchers identified Srizbi variants compiled as early as March 31, 2007, and later traced older Srizbi samples back to April 2007, indicating the malware was in circulation by spring 2007.
Arbor Networks researchers reported that StormWorm bots were launching distributed denial-of-service attacks against Srizbi domains, showing conflict between major botnet operators.
Investigators identified 16 additional nearby servers controlling different Srizbi variants, indicating the botnet was segmented and likely rented to multiple customers for separate spam campaigns.
Analysis of recently compromised machines showed that Srizbi was being distributed through the n404 web exploit kit via the malicious site msiesettings.com. The installer also fetched a remote configuration file with URLs for additional malware downloads.
Examination of the seized controller software showed that Srizbi served as the mailing component of Reactor Mailer, a spamware platform operated by the spammer 'spm.' The investigation also found a customer account named 'nenastnyj' and a saved task 'RonP_3' linked to the Ron Paul spam run.
With assistance from Spamhaus, researchers shut down a Srizbi command-and-control server and obtained its running Python controller software for analysis. This enabled deeper investigation into the botnet's operation.
After tracking several thousand sending IPs and analyzing distinctive email header fingerprints, researchers identified Trojan.Srizbi as the malware behind the Ron Paul spam botnet and traced its command-and-control server to a U.S. co-location facility.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.