Spam, after a holiday hiatus, returns in earnest

The holiday break appears to have ended for those behind the world's largest spamming operation.

The Rustock botnet, dubbed the largest source of global spam, has resumed activity after a two-week hiatus during which time spam amounts drastically fell, according to security researchers at Symantec.

On Christmas day, the botnet went quiet, but on Monday the botnet resumed operations and once again began distributing pharmaceutical spam. According to security firm NetWitness, the messages are attempting to push Viagra from "shady" sites ending in the .ru domain.

The messages are being sent with subject lines such as "Dear [username] -80% now," security researchers from Symantec Hosted Services wrote in a blog post Monday The messages direct users to click on a link that takes them to a fraudulent website called "Pharmacy Express."

Researchers believe the botnet is poised to quickly return to pre-Christmas spam output levels.

“While levels of Rustock output appear marginally lower than before Christmas, we see no reason they won't reach those previous levels again, bringing global spam levels back up to the approximately 90 percent levels [off all emails] we had become so used to,” Symantec researchers said.

Meanwhile, spam output from two other major botnets, Xarvester and Lethic, also declined during the holiday season. Xarvester also since resumed delivering junk mail after its short break, which began on Dec. 31.

More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.