/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

The Inside Story of the Kelihos Botnet Takedown

Earlier this week, Microsoft released a n announcement about the disruption of a dangerous botnet that was responsible for spam messages, theft of sensitive financial information, pump-and-dump stock scams and distributed denial-of-service attacks.

threatpost Tillmann Werner

Context & Ripple Effects

This is Microsoft's second major botnet strike in just over a year. In September 2010 the company ran the Waledac takedown, pairing court orders with server seizure to cut off a spam network at its command layer — and Kelihos is the follow-on application of that same playbook, this time against a botnet tied to spam, theft of sensitive financial information, pump-and-dump stock scams, and distributed denial-of-service attacks.

First-order effects

  • Kelihos-infected machines are severed from their command-and-control servers, immediately degrading the network's capacity to push spam, harvest financial credentials, and run pump-and-dump and DDoS operations.

Second-order effects

  • The operators behind Kelihos face the same pressure Waledac's did: rebuild or rebrand their infrastructure elsewhere, while defenders study how quickly the replacement comes online as a measure of whether takedowns actually reduce criminal capability or merely relocate it.

Third-order effects

  • If the Waledac-to-Kelihos sequence holds, private companies acting with civil-court authority become a standing enforcement channel against criminal botnet infrastructure — a model that sits between individual endpoint antivirus and slow-moving criminal prosecution.

The trend: Botnet defense is shifting from per-machine cleanup to coordinated legal-and-technical takedowns of command infrastructure, with Microsoft establishing itself as the recurring private enforcer.