What Was the Storm Worm? The Botnet With No Head

Subject: 230 dead as storm batters Europe. Attachment: Full Story.exe, or Read More.exe, or Video.exe.

It was Friday, 19 January 2007. The storm was real. It had crossed Germany and the Netherlands the previous afternoon and Poland overnight, with gusts over 200 km/h, and it had killed people. The number in the subject line was not the number of people it had killed, but it was the kind of number a Friday morning headline carries, and the email was in the inbox before most of Europe had read a newspaper.

Everyone remembers the Storm Worm. It was not a worm.

What was the Storm Worm?

A backdoor trojan for Windows, discovered on 17 January 2007 and named by F-Secure two days later when the storm spam began. It arrived as an executable attachment on an email whose subject line was a plausible news headline. Open it, and the machine joined a botnet.

That is the whole delivery mechanism. There was no vulnerability, no exploit, no self-propagation. Nothing scanned a network. The trojan mailed copies of itself out, and the copies waited for someone to double-click. It spread the way ILOVEYOU had spread seven years earlier, on curiosity, and the only thing that had changed was the bait: not a love letter, but the news.

Calling it a worm was a category error that stuck because the word was in the name. What made Storm interesting was not how it got in. It was what it did once it was there.

The subject lines

The Kyrill headline was the first of the weekend, not the only one. The same wave carried, among others:

  • A killer at 11, he's free at 21 and kill again!
  • U.S. Secretary of State Condoleezza Rice has kicked German Chancellor Angela Merkel
  • Saddam Hussein alive!
  • Chinese missile shot down USA aircraft
  • Naked teens attack home director.

Some of those are news that never happened. That was fine. The recipient did not need to believe the story; they needed to want to see the video, and the attachment was the video. The storm one worked best because it was true, and because the real number, forty-seven, was close enough to 230 that nobody paused.

The botnet with no head

Every botnet before Storm had a command server. Infected machines connected to an IRC channel or an HTTP address to receive instructions, which meant every botnet had exactly one point where it could be killed: take the server, sinkhole the domain, and the army goes deaf.

Storm did not have one. Its bots found each other over Overnet, a Kademlia-based peer-to-peer protocol originally built for eDonkey file sharing. Each infected machine kept a list of thirty or so other infected machines and asked them where to find the latest commands. No node held the full roster. No node was special. Seize any one of them, seize a thousand, and the rest of the network did not notice.

The web side was built the same way. The spam it sent pointed at domains whose DNS records rotated every few minutes through the addresses of infected home machines, each one proxying for a hidden server behind it. Fast-flux, the technique is called, and Storm was the network that made the term common. Block the address and it had already changed. Block the domain and there were more.

Joe Stewart at SecureWorks, who spent most of 2007 inside it, reported that the trojan changed its packing code every ten minutes, so the binary on disk was different every few minutes and antivirus signatures were stale before they shipped. Infected machines also ran a rootkit and disabled security software.

It attacked the people studying it

This was new. Researchers who scanned Storm nodes, or probed the peer-to-peer network too aggressively, found their own addresses under denial-of-service attack within hours. Josh Corman at IBM Internet Security Systems described it publicly in October 2007: the botnet appeared to identify hosts investigating it and retaliate automatically. Anti-spam organisations reported the same. The botnet was, in short, engineered by someone who had studied how the previous botnets had died and had given this one a way to fight back.

How big was it?

This is the number everyone quotes and nobody can settle, so it is worth being precise about what was measured.

  • By 22 January 2007, three days into the spam run, F-Secure reported Storm accounted for 8% of all malware infections worldwide.
  • In September 2007, at what is generally taken as its peak, published estimates of the botnet's size ran from one million to ten million machines. Some press coverage went higher.
  • Researchers at the University of Mannheim and Institut Eurecom, who crawled the peer-to-peer network directly and counted what they could actually see, put the number of bots concurrently online at between 5,000 and 40,000.

The two ranges are not in conflict. The first counts machines that had been infected at some point and might answer a command eventually; the second counts machines online and reachable at a given moment. A botnet's capacity to send spam is closer to the second number. Its capacity to alarm a conference audience is closer to the first.

The honest statement is that it was the largest peer-to-peer botnet anyone had measured, that its size was genuinely unknowable from outside, and that anyone who gave you a single number was choosing which one to give.

What it was for

Money, in the ordinary way. Storm sent spam: pharmaceutical, pump-and-dump stock promotion, and, recursively, more Storm. Portions of the botnet were rented out. When Bruce Schneier looked at reports in October 2007 that the network was shrinking, his read was that it was not shrinking but being partitioned, split into segments with separate encryption keys so that the parts could be sold or leased independently. A botnet the size of Storm, in other words, was being turned into inventory.

It faded through 2008 as the peer-to-peer traffic became easier to fingerprint and as Microsoft's Malicious Software Removal Tool started cleaning it in bulk. Its successor, Waledac, appeared at the end of that year with the same spam business and a rebuilt network, and Microsoft took Waledac down in court in February 2010. The people behind either have never been identified.

The bait was the news

When the storm was old news, the subject lines changed. A missile strike. A war with Iran. A greeting card from a friend, in time for Valentine's Day. An NFL tracker in September. A Halloween game, a Christmas card, a New Year's greeting, a YouTube link. Each wave was a headline or a holiday, timed to the week, and each one carried the same trojan with a different wrapper.

The people who opened the Kyrill attachment were not being careless. The storm had killed forty-seven people the previous day and every news site in Europe was leading with it. The email was a story about the thing everyone was already reading about, and it had arrived three hours before the papers.

It never needed a bug. It needed a Friday and a weather report.

Further reading

  • Thorsten Holz, Moritz Steiner, Frederic Dahl, Ernst Biersack, Felix Freiling — Measurements and Mitigation of Peer-to-Peer-based Botnets: A Case Study on Storm Worm, USENIX LEET 2008.
  • Joe Stewart, SecureWorks — Storm Worm DDoS Attack, February 2007, and the follow-up analyses through 2007.
  • Bruce Schneier — Gathering 'Storm' Superworm Poses Grave Threat to PC Nets, Wired, 4 October 2007.
  • Pierre-Marc Bureau and Andrew Lee, ESET — The Passing Storm: The Storm/Nuwar Botnet, Virus Bulletin 2007.
  • F-Secure Weblog, January 2007 — the original naming and the first-week infection figures.

EXHIBIT 0027 — STORM WORM

We put it on a shirt. An antique aneroid barometer in a turned wooden case, drawn as an engraving, its pointer swung hard past STORMY to the end of the dial.

Callouts: NOT A WORM. A TROJAN IN AN ATTACHMENT. REPACKED EVERY TEN MINUTES. NO COMMAND SERVER TO SEIZE. And the one that is the actual point: KYRILL KILLED 47. THE SUBJECT SAID 230.

The headline was the payload.

That's the whole idea.

View the Storm Worm shirt — EXHIBIT 0027

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.