September 29, 2016 By Larry Loeb < 1 min read

Spamhaus and SpamCop serve as blocklist generators for mail servers all over the internet. They both deal with the unwanted spam that affects users, much of which is fairly innocuous.

But since cybercriminals do generate spam as part of their attachment-spreading campaigns, keeping spam under control means avoiding spam network hijacking.

Spam Network Hijacking Spikes

Spamhaus recently warned that it observed a spike in network hijacking in support of spam campaigns. Specifically, the company is most concerned about the Border Gateway Protocol (BGP) hijacking it detected, Softpedia reported.

This type of hijack causes an internet service provider (ISP) to falsely announce to all other service providers that an IP range has been found on its network. The ISP can then receive the traffic destined for that range of IP. Perhaps more importantly to the spammer, it can send traffic that uses the IP address space of the hijacked network.

Spamhaus has seen this activity grow over the last three years, but the impetus for the growth may not be readily apparent. One reason for the rise in hijacking is the shrinking pool of IPv4 addresses available to spammers. If a blocking service bans a spamming address, the spammer has limited choices with which to replace it.

It seems that BGP hijackers like to take over legacy IP ranges. The true legacy owners may not care about their IPv4 space anymore, making them an easy target.

Spam Wars in Full Swing

Softpedia further noted that the American Registry for Internet Numbers (ARIN) had similarly sounded the alarm in June about an increase in IPv4 range hijacks. The group said that criminals were registering fake companies or re-registering old domain names without the authority to take over the older IPv4 ranges.

As the spam wars reignite, alternative methods of spam determination may prove useful when a blocklist alone isn’t enough.

More from

Router reality check: 86% of default passwords have never been changed

4 min read - Misconfigurations remain a popular compromise point — and routers are leading the way.According to recent survey data, 86% of respondents have never changed their router admin password, and 52% have never adjusted any factory settings. This puts attackers in the perfect position to compromise enterprise networks. Why put the time and effort into creating phishing emails and stealing staff data when supposedly secure devices can be accessed using "admin" and "password" as credentials?It's time for a router reality check.Rising router risksRouters…

Preparing for the future of data privacy

4 min read - The focus on data privacy started to quickly shift beyond compliance in recent years and is expected to move even faster in the near future. Not surprisingly, the Thomson Reuters Risk & Compliance Survey Report found that 82% of respondents cited data and cybersecurity concerns as their organization’s greatest risk. However, the majority of organizations noticed a recent shift: that their organization has been moving from compliance as a “check the box” task to a strategic function.With this evolution in…

The 5 most impactful cybersecurity guidelines (and 3 that fell flat)

4 min read - The best cybersecurity guidelines have made a huge difference in protecting data from theft and compromise, both in the United States and around the world.These guidelines are comprehensive sets of recommended practices, procedures and principles designed to help organizations and individual people safeguard their digital assets, systems and data from malicious attacks. They can cover a wide range of practices and exist in part to collect and share best practices and strategies based on industry standards and expert knowledge. Crucially,…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today