Grum, also known as Tedroo, was a large spam-sending botnet active in the late 2000s and early 2010s. It operated as a criminal spambot platform composed of infected systems remotely controlled through centralized command-and-control infrastructure. At its peak, Grum was one of the world’s most significant sources of unsolicited email, at times surpassing other major spam botnets in share of global spam volume and being assessed as the third-largest spam botnet before its 2012 disruption.
Grum’s primary function was mass spam distribution. Reporting associated it with very large bot populations and sustained high daily volumes of spam-sending hosts. The botnet used segmented command-and-control architecture, with infrastructure observed across multiple countries, and operators demonstrated the ability to reconstitute control rapidly by standing up replacement controllers after takedown actions. Some infected hosts were unable to send outbound email because of network restrictions and were instead used for other botnet-related tasks such as hosting promotional content, indicating flexible post-compromise use of infected systems.
Grum was the subject of a coordinated takedown in July 2012 involving FireEye, Spamhaus, CERT-GIB, and other collaborators. Defenders first disrupted parts of its infrastructure and then tracked the operators’ attempts to migrate command-and-control to new servers, enabling follow-on shutdowns. After the operation, all known controllers were reported offline, spam activity dropped sharply, and the remaining infected systems were described as orphaned zombies without functioning control infrastructure. Subsequent monitoring indicated that Grum was effectively dead.
Grum is best characterized as a spambot botnet used for large-scale email abuse rather than a malware family known primarily for credential theft, ransomware deployment, or espionage. The available information supports its role in spam operations on compromised Windows endpoints, but does not provide high-confidence evidence for more specific secondary capabilities beyond botnet control and spam-related post-exploitation activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Overall, Symantec’s new report notes that Spam levels jumped to 89.4 percent in February... The cause for the jump is due largely to the Grum and Rustock botnets...
After seeing the Panamanian server had been shut down, the bot herders moved quickly and started pointing the rest of the CnCs to new secondary servers in Ukraine.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A historic spambot mentioned only as background and comparative context.
A spambot family mentioned among various spambot command-and-control families tracked by Spamhaus.
A spam-sending botnet used to distribute large volumes of spam via infected hosts controlled through command-and-control servers.
Grum is a spam botnet used to control large numbers of infected systems for sending spam and hosting promotional websites via command-and-control infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.