People often ask me how spam can be sent and why does it exist. Spam email costs business money and time. We don’t want it and never read it (do we?) so how can we stop it.
I do not think that we will ever be able to stop it is my answer, every time we provide a solution to stop it, the people that send it come up with another way to make it difficult to filter it out.
One of the most common ways that spammers are able to be non detectable are using your machine without you realising to send the spam email or attack other machines on the internet with so much traffic that the service is knocked offline.
Quite often without you realising you have installed an infected piece of software that has given backdoor access to your machine to these spammers. This is referred to as Zombie or Bot networks.
The most common methods used to distribute infected software are Trojan droppers and downloader’s installed into pirate software which is distributed via file sharing P2P networks (Kazaa, eDonkey, MSN messenger etc.). Or exploiting vulnerabilities in MS Windows and popular applications such as Internet Explorer, Instant messenger programs and Outlook. Hence do not innocently install software on your work computer that has not been approved by more experienced people that are able to test and approve, i.e. your IT administrator.
The people that have the control part of a program which controls the Trojans can then sell their access to all these machines to the spammers or people that want to use your machine connected to the internet to attack another network or website to take it offline. Because the attacks and spam email would be coming from many machines on the internet it is hard to combat/ detect.
Analysts estimate that Trojans are installed on millions of machines worldwide. Modern Trojans are sophisticated enough to download new versions of themselves, download and execute commands from specified websites or IRC channels, send out spam, conduct DDoS (denial of service) attacks and much more.
How is spamming profitable?
1% of a few million emails is a lot of possible business, and believe it or not some people do click on the links in the emails since they are intrigued about a cheap mortgage deal or pirate software that does lead to business and it costs them nothing really to send the emails. And a lot of the dark people that write virus for the challenge have the same mental attitude to write a spam engine that is successful without been detected.