Technology moves fast. Context matters. Independent by design ↗

Find your next rabbit hole.

Explore the collection, or type to search.

ExplainerYahoo closes GeoCities: how the web lost millions of home pagesYahoo bought GeoCities for billions in 1999 and switched it off a decade later. The closure became a turning point for web preservation.ExplainerThe Storm worm: the botnet that started with a weather headlineIn January 2007 an email about deadly storms in Europe spread a Trojan that built one of the largest peer-to-peer botnets of its time.ExplainerGPLv3: how the free software licence was rewrittenAfter 18 months of public drafting, the Free Software Foundation published version 3 of the GNU General Public License in June 2007.ExplainerThe UK identity card scheme: from Act of Parliament to shredded registerBritain legislated for national ID cards backed by a central biometric register, then abolished the whole scheme within five years.ExplainerThe netbook era: small, cheap laptops that briefly drove PC growthThe Asus Eee PC started a boom in low-cost mini laptops that propped up PC sales, until tablets and thinner laptops took their place.

Press Esc to close

2007 · Security

The Storm worm: the botnet that started with a weather headline

Last reviewed 5 October 2026

In January 2007 an email about deadly storms in Europe spread a Trojan that built one of the largest peer-to-peer botnets of its time.

How it began

In January 2007, as a severe windstorm hit Europe, inboxes filled with messages carrying headlines about storm deaths. The attachment was a Trojan for Windows. The timely subject line gave the malware its name.

Later waves used whatever was topical: e-cards, news alerts, holiday greetings and fake video links. The lures changed constantly, which made simple subject-line filtering ineffective.

Why it was different

Earlier mass-mailing worms were mostly about spreading. Storm was about building a resilient botnet. Infected machines communicated over a peer-to-peer network rather than a single control server, which made it much harder to shut down.

The network was rented out for spam and used for distributed denial-of-service attacks, including against researchers who probed it. Estimates of its size varied enormously, from hundreds of thousands to millions of machines, because a peer-to-peer botnet is hard to count.

Decline

By late 2007 researchers reported that Storm’s active population was shrinking, helped by antivirus updates and Microsoft’s Malicious Software Removal Tool. Its operators were never publicly identified. Its peer-to-peer design and fast-changing lures influenced the botnets that followed.

Sources

  • Wikipedia: Storm Worm
  • Microsoft Malware Protection Center reports on Win32/Nuwar, 2007
  • Academic and vendor analyses of the Storm peer-to-peer botnet, 2007–2008

More on Security