Lethic

Malware

⚠️ Overview

Lethic is a spam‑sending botnet first identified in mid‑2007 by security researchers, widely attributed to Russian‑speaking threat actors associated with the Russian Business Network (RBN). It belongs to the botnet category, primarily designed to relay bulk spam email—notably pharmaceutical spam—by compromising Windows systems through drive‑by downloads and exploit kits.

🔧 Technical Capabilities

Lethic features a decentralized command‑and‑control (C2) architecture using a custom peer‑to‑peer protocol over TCP port 80 and 443, making it resilient to single‑point takedowns. Infection vectors include malicious web redirects via compromised ad networks, as well as exploitation of outdated browser plugins (e.g., Adobe Flash and Java). Once installed, the malware establishes persistence by adding a registry run key under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun and communicates with a tiered network of proxy nodes and worker bots. Evasion techniques include polymorphism in its binary payload and the use of HTTP requests with a specific User‑Agent string (Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)) to blend with legitimate traffic. The botnet’s custom protocol encodes commands and reports status via GET requests to paths such as /cgi‑bin/bt.cgi?cmd=info&ver=1.0, as documented in the academic paper Lethic: A Botnet Under the Microscope (Stone‑Gross et al., 2011, IEEE Symposium on Security and Privacy).

📜 History & Notable Incidents

Discovered in 2007, Lethic grew to an estimated 30,000 active bots by early 2010. A major campaign in 2009‑2010 pushed “Canadian Pharmacy” spam, flooding inboxes globally. No high‑profile victims or CVEs are publicly associated with Lethic itself, but its takedown was achieved in 2010 when researchers from the University of California, Santa Barbara, and Dell SecureWorks conducted a sinkhole operation that redirected bot traffic, effectively dismantling the network (Stone‑Gross et al., 2011).

🔍 Detection Indicators

Network indicators include outbound HTTP GET requests to /cgi‑bin/bt.cgi with parameters cmd=info, cmd=spam, or cmd=poll, using the User‑Agent noted above. File‑system artifacts may include a randomly named executable in %APPDATA% and a registry value under HKLM...Run pointing to that path. Known MD5 hashes of early samples are sparse, but behavioral signatures involve persistent SMTP connections to multiple distinct mail relays and a CPU spike during spam‑send cycles.

☠️ Risk & Impact

Lethic’s primary damage was the propagation of billions of pharmaceutical spam emails, which facilitated illegal drug sales and inflicted reputational harm on legitimate email infrastructure. The botnet also contributed to denial‑of‑service degradation on mail servers and was implicated in distributing secondary malware payloads via spam attachments. Affected sectors include telecommunications, web hosting, and consumer internet services.

🛡️ Mitigation

Mitigation relies on blocking outbound HTTP requests to known sinkholed IP ranges, enforcing email‑filtering ACLs, and deploying endpoint detection rules that flag the specific User‑Agent string and HTTP path patterns. Organizations should also patch browser plugins and apply Windows registry‑monitoring rules to detect the persistence mechanism. No public CVE patch exists; defenses are behavioral and network‑based.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.