Microsoft has denied that the Kelihos botnet is back in operation. A new malware that shares similar traits with Kelihos has appeared though.
Microsoft has come back to the subject of Kelihos rising from the ashes, by providing additional information. For Microsoft, who was the architect of the dismantling of the botnet with the help of Kaspersky Lab and Kyrus Tech, the botnet is not back from the grave.
Richard Domingues Boscovich from Microsoft’s Digital Crimes Unit declares: "Contrary to some reports, Kaspersky and Microsoft have no evidence that the botnet that was taken down in September has returned to the control of cybercriminals or is spamming again at this time."
First seen in a Kaspersky Lab’s report, the confusion has come from the fact that a new malware is currently being spread, with this being a "slightly updated" variant of the malware which allowed for the initial construction of the Kelihos botnet. This variant is therefore being used to try and create a new botnet.
Such attempts at renewing the botnet will be relatively frequent. Kelihos itself was built from part of Waledac’s code, the first botnet that Microsoft dismantled in February 2010.