Storm, also known as the Storm worm or Storm botnet, was a major Windows-based spam botnet and peer-to-peer malware operation that emerged in 2007 and became one of the most prominent early public examples of a large-scale P2P botnet. It propagated through aggressive social-engineering campaigns, especially spammed e-card lures and other themed email messages, and used fast-flux hosting and rapidly changing variants to complicate blocking and signature-based detection. Storm is widely regarded as an important precursor to later spam and malware botnets, and some reporting describes Waledac as a successor or rewrite that reused several of its techniques.
Storm combined mass-malware distribution with resilient botnet operations. Its architecture used encrypted peer-to-peer command and control rather than relying solely on centralized infrastructure, improving survivability against takedown efforts. The botnet was used extensively for bulk spam operations and was associated with harvesting personal information and credentials from infected systems. Reporting also links its operators to broader cybercrime monetization ecosystems, including rogue pharmacy spam operations. Storm additionally demonstrated defensive and offensive botnet capabilities beyond spam: infected nodes could participate in distributed denial-of-service activity, including retaliatory attacks against systems attempting to scan for or disrupt infected hosts.
The malware primarily targeted Microsoft Windows systems. Contemporary reporting and later law-enforcement statements have associated Storm with Russian spam operator Peter Yuryevich Levashov and with actors tied to the SpamIt/Glavmed ecosystem, although attribution in historical reporting is not uniform. Storm’s bot population declined through 2008 under sustained disruption pressure, including defensive cleanup efforts and researcher interference, and the botnet is generally considered to have ceased operating in September 2008. Its significance endures because it helped establish patterns later seen in major botnets: P2P resilience, encrypted control channels, fast-flux support infrastructure, high-volume spam delivery, credential harvesting, and adaptive evasion against defenders.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The Department of Justice said that Levashov “controlled and operated multiple botnets, including the Storm, Waledac, and Kelihos botnets to harvest personal information and means of identification (including email addresses, usernames and logins, and passwords) from infected computers.”
Its main brand is the notorious ‘Canadian Pharmacy’, which is all too familiar to everyone through massive email spam campaigns that seem never to end.
The members of SpamIt are allegedly the group behind the Storm, Waledec and potentially Conficker botnets, responsible for email distribution and fast-flux hosting of the spam websites
Feed in a Google Refresh Token and a geographically matched SOCKS5 proxy, and the panel silently restores the victim's authenticated session.
Origins P2P networks are more scalable and robust than traditional C/S structures, and these advantages were recognized by the botnet authors early on and used in their botnets.
“For over two decades, Peter Levashov operated botnets which enabled him to harvest personal information from infected computers, disseminate spam, and distribute malware used to facilitate multiple scams,” said Assistant Attorney General Brian Benczkowski in a statement.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a comparison family that did not technically match the observed sample.
A worm-associated botnet used for large-scale spam and DDoS activity. The content describes it as capable of launching distributed denial-of-service attacks against systems scanning for vulnerabilities or malware, and notes its operators also shifted from email lures to malicious web pages.
Storm is an infostealer that harvests browser credentials, session cookies, crypto wallets, documents, messaging app session data, system information, and screenshots. It avoids local browser credential decryption by exfiltrating encrypted browser data to attacker-controlled infrastructure for server-side decryption, and supports automated session restoration using stolen tokens and proxies.
Mentioned only in a related video/source title, not discussed in the transcript content itself.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.