Cisco releases Malware Report for the fourth quarter 2010
Cisco has released a report built from data gathered from its RMS and IPS products at enterprise clients, with some surprising results regarding the age of the threats detected:
The greatest activity from a botnet was the Rostock botnet, first seen in 2006.
Conficker, MyDoom, Nachi and Slammer worms are still active, despite defensive measures implemented years ago.
The Gbot botnet activity increased in the last quarter of 2010, perhaps indicating dominance in the coming months. Gbot transfers command and control signals via HTTP instead of SSH and IRC.
Confirming other security vendors,
The short (9 page) report is worth a look: Global Threat Report