Originally published Monday, December 3, 2007 at 12:00 AM
Upstart Storm swiftly gained Web strength
If Rock Phish is the Microsoft of the cybercrime world, Storm is akin to Google: the upstart that has quickly gained enormous reach and...
San Jose Mercury News
If Rock Phish is the Microsoft of the cybercrime world, Storm is akin to Google: the upstart that has quickly gained enormous reach and the potential to generate loads of cash.
Its meteoric rise has left security experts unsure who is behind Storm, and why such an enormous botnet was built.
It started in late January, with messages bearing a simple subject line: "230 dead as storm batters Europe." Hurricane-force winds were blowing through Europe at the time, and Internet users across the continent clicked on the file attachment to learn more — unwittingly allowing the cybercriminals known as the Storm Worm group to take control of their computers.
Other enticing e-mails followed, spreading around the world in waves. There were headlines about the death of President Bush and war breaking out against Iran.
Some of the most successful arrived as e-greeting cards: Users thought they were receiving Easter or Fourth of July wishes from friends. Other messages lured users to a Web site packed with NFL stats — and filled with malware.
In just a few months, Storm created a network that Peter Gutmann, computer-science professor at the University of Auckland in New Zealand, estimates has more power than the world's largest government and corporate supercomputers. No one knows for sure how large: Many security researchers put the number at more than 100,000; some say 50 times that.
Security experts wonder why Storm has built such an enormous botnet. Cloudmark researcher Adam O'Donnell believes the goal was merely to build the network for rental to criminal enterprises.
Large botnets can be used to launch massive scams, including e-mail pump-and-dump schemes, in which criminals purchase cheap stocks, trick others into buying to briefly drive up the price, and then unload them at a profit. They might also capture passwords and account information stored within infected computers.
Experts are similarly uncertain who created Storm. Some data has pointed toward servers in China, and a Chinese woman's name was used to register some domains. Others believe it's headquartered in Russia.
But there is not much solid evidence. "We have no idea where the heck these guys are," said Arbor Networks' Jose Nazario.
Copyright © 2007 The Seattle Times Company
UPDATE - 09:46 AM
Exxon Mobil wins ruling in Alaska oil spill case
UPDATE - 09:32 AM
Bank stocks push indexes higher; oil prices dip
UPDATE - 08:04 AM
Ford CEO Mulally gets $56.5M in stock award
UPDATE - 07:54 AM
Underwater mortgages rise as home prices fall
NEW - 09:43 AM
Warner Bros. to offer movie rentals on Facebook

The 2014 Jeep Grand Cherokee SRT has 470 horsepower and a luxurious interior. (Chrysler) There's a new Jeep Grand Cherokee from Street and Racing Tech...
Post a comment
- Paula Deen says she used slur but doesn’t tolerate hate
- Men's Wearhouse ousts founder, pitchman Zimmer
- Many questions, few answers in death of Bellevue massage therapist
- U.S. men beat Honduras in World Cup qualifying match
- Microsoft retreats on rules for Xbox One after gamers complain
- Fasting woman to end attempt to ‘live on light’
- Temporary I-5 bridge opens to traffic
- Man charged with tossing wife off cruise ship
- Reporter who broke story on Gen. McChrystal dies in crash
- Seattle jobless rate under 5% for the first time since 2008
- Game thread: Mariners hope to secure a winning road trip
275 - Why the Mariners are taking so long with Dustin Ackley
228 - Most hate their jobs or have ‘checked out,’ Gallup says
140 - Mariners survive game of bullpen roulette
109 - Seattle jobless rate drops below 5%
107 - Guest: Boeing’s exodus from Washington state
69 - Price, Parker to represent UW at Pac-12 Media Day
62 - Parents' ruse snares older Federal Way man wooing daughter
49 - DOJ urged to avoid pot showdown with state
48 - Senator: IRS to pay $70M in employee bonuses
46
- Most Americans hate their jobs or have 'checked out,' Gallup says
- Wheat scare leaves farmers in limbo
- Temporary I-5 bridge opens to traffic
- Seattle jobless rate under 5% for the first time since 2008
- Microsoft retreats on rules for Xbox One after gamers complain
- ‘Wonderful theatrical experience’ key, says new Seattle Opera leader
- Seattle startup Tred delivers car test drives
- ‘I don’t want to be only person cured of HIV’
- Recipe: Lemon Poppy Seed Pound Cake
- Fasting woman to end attempt to ‘live on light’







