The majority of spam people see contains a link to some sort of pharmacy or replica website, offering the recipient cheap Viagra, weight loss pills, dating sites, Rolex watches or designer handbags. Most of these websites are designed around a brand created by an affiliate program which affiliates are paid, usually on commission of sales, to promote.
About seven months ago we posted a blog about our survey of affiliate brands in spam and determined that Canadian Pharmacy was by far the most spammed brand with over 60 percent of all spam containing links to Canadian Pharmacy websites. The next closest brand, Prestige Replicas, was advertised in less than 10 percent of spam.
In the last month a pharmaceutical brand named Canadian RX Drugs has overtaken Canadian Pharmacy as the most spammed affiliate brand, stealing almost half of the market share that Canadian Pharmacy once held. Another brand, Dr Maxman, has also increased from less than one percent to just over 10 percent.
The chart below is from a sample taken from spam we have received over the past seven days and only from spam that contains links to a website. All percentages will be slightly lower when considering total spam.
Casino Generic is the name we have given to a group of casino brands such as King spin, Golden mummy, Ruby royal and Seven stars, all available from a single affiliate program. These casino brands are usually promoted by the Maazben botnet.
Casino Websites we categorized as 'casino generic'
Other than Mega-D and Maazben which exclusively spam out links to Canadian Pharmacy and Casino websites respectively, the top spam botnets promote a range of brands. This could either be because the botnet controllers belong to multiple affiliate programs or because they rent out spamming capacity to different people who are affiliates trying to promote their chosen brand.
The table below shows which, of the top six affiliate brands, promoted in 90 percent of spam in the last week, was sent by the top spam botnets.
Some of the botnets involved in sending this stuff have a huge amount of spamming capacity, like Rustock which is currently sending around 40 percent of the spam we see. As such, botnet operators have the ability to greatly influence the market shares of affiliate programs simply by changing their spam templates. So with a flick of a switch, what we see today could easily be different tomorrow.