50% of the World’s Spam Gone?

According to CNN and a couple of other sites this week, 50% of the world’s spam has disappeared from the face of our little green and blue ball of dirt, thanks to the takedown of yet another botnet, this time a nasty little fella named Grum.

According to CNN, Atif Mushtaq, a senior scientist at security firm FireEye, the company responsible for taking Grum offline, stated that:

“about 50% of the worldwide spam is gone.”

Now, before you celebrate by logging out of Facebook and donning your water wings – stop. As sexy a number as 50% is, unfortunately it appears to be wrong.

Most reports have the number at a more realistic, less sexy sounding 17% or so, suggesting that CNN must have employed NASA scientists who falsely assumed that the time difference between California (where FireEye is located) and Atlanta (where CNN is located) means that percentages are subject to some sort of Metric to U.S. conversion. It leads to a whole debate on getting one’s facts straight and taking a deep breath before hitting the ‘publish’ button, but that’s a debate for another day.

The fact still remains that FireEye did disable Grum’s C&C servers this week. According to articles not subject to NASA scientists and sensationalist reporting, Grum is the world’s third largest spam network, responsible for about 17% of the spammy goodness invading your Inbox each day. It was a little dicey at first, according to FireEye, when servers that were shut down in Panama and Russia were quickly replaced by new servers in the Netherlands and the Ukraine. Along with Spamhaus, the Russian computer security incident response team CERT-GIB, and an anonymous researcher known only as Nova7, FireEye was able to convince the affected ISPs (and in the case of Russa, an upstream provider) to null route the site’s IP addresses, and voila! No more Grum, for now, anyway.

The shutdown represents the unceremonious end of a botnet that’s been skulking around since 2008, an unusually long time for a botnet. As late as earlier this year, Grum was responsible for about a third of the world’s spam, according to Mushtaq. But at the time of the takedown, Grum was reported to be shoveling 17.4% of the Internet’s crap:

“making it the world’s third most active spam botnet after Cutwail and Lethic,” Mushtaq wrote. He highlights some of the high points and low points of Grum and the difficulties encountered in taking it down, for example, employing the assistance of countries like Russia, Panama, and the Netherlands, where “authorities historically have been reluctant when dealing with abuse notifications.”

Ultimately, Mushtaq doesn’t regard Grum’s shuttering as much of a challenge.

“If I were to rank Grum’s takedown difficulty level from one to five where five is the most difficult, I would give Grum a two,” he stated.

He goes on to wax poetic about a spam free world, perhaps in a moment better suited for a beauty pageant:

“Can we dream of a junk-free mailbox? In my opinion, taking down the top three spam botnets—Lethic, Cutwail, and Grum—is enough for a rapid and permanent decline in worldwide spam level.”

Nice thought. Maybe he’ll get the Miss Congeniality prize.

Now it’s time for you to weigh in. Are you seeing dramatic drops in spam volumes?

Written by Malcolm James


  1. Sweet Milano · July 23, 2012

    Although I am all for celebrating small victories and all (this is not just a small victory, by the way), I also don’t want to linger much on a party or rest on laurels.

    Even if let’s say the accurate figure is 50%, there is still more to be done to take it out. Remember, taking down a bunch of small operations permanently is more difficult. Why? Because those operations are small, it is easier to restart. That’s why cells are better in tactical operations than a huge network. After all, elephants don’t dance.

    So, let’s press on. There is still the other 50% to work on. Or 83%, if we take CNN’s figures.

  2. Jessica Craig · July 24, 2012

    Hahaha! Good laugh! C’mon, can anybody believe this? Judging by the amount of spam in my inbox, I must be living on another planet because even if there is increase in global spam, it seems it has missed my inbox. This 50% thing sounds more like an election claim to me. This can’t be true, these people are not serious, or they are troubled in some way to say such incredible things.

  3. Danilo Samuelson · July 28, 2012

    Game over? Not yet.

    I’m sure we’ve tried playing a game or two. Winning means taking out the opponent. 50% is hardly a real victory. But, I understand the premature celebration. It is a hard battle, after all. It is a hard, protracted and complicated battle, indeed. And truth be told, the economic benefits of those fighting against spam is less than the benefits of successfully spamming people off their data and money.

    And, yes, I understand Jessica’s skepticism. I still see some spam in my inbox for some of my accounts. But I’m curious, Jessica. Which email account are you talking about? Work-related, Yahoo, Gmail, Hotmail?

Leave A Reply