Latest Bugbear virus aims at bank networks

By Staff, ZDNet Asia
Wednesday, June 11, 2003 09:45 AM
Security firm Symantec has uncovered a sinister new function in fast-spreading email virus Win32.Bugbear.B which suggests the worm harvests passwords used by bank employees.

"We have discovered a previously unknown functionality within the 32Bugbear.B worm and is strongly advising financial institutions worldwide that they may be at greater risk of exposure," antivirus software firm Symantec said in a statement.

The company said on its Web site this new discovery specifically affects employees of financial institutions.

When the worm finds names of banks in a victim's mailbox, it tries to send sensitive data such as cached passwords and keystrokes to one of 10 public e-mail addresses included in its code.

The Win32.Bugbear.B belongs a new, worrying class of email worm that not only attempts to clog networks through malicious replication, but also attempts more serious forms of criminal activity.

According to a report from the Associated Press, the U.S. government has issued a similar warning and the FBI is currently looking to what security experts believe to be the first Internet attack aimed at a specific economic sector.

The report said professionals who studied the make up of the new Bugbear worm have found a list of about 1,200 Web addresses for many of the world's largest financial institutions in its code. These include JP Morgan, American Express and Citibank.

These experts believe the BugBear software was programmed to scan mailboxes looking for signs that the victim is a bank employee. If there is a match, the worm then steals passwords and other information and sends them to the 10 e-mail addresses, making easier to compromise the bank's network in future, said the report.

No major bank has yet to report a security breach as a result of the worm, according to news reports.

Soon after it surfaced last Wednesday, security software firms have upgraded the Win32.Bugbear.B virus from a medium level threat to high due to the rapid rate of infection.

To date, Symantec said it has received 8,932 reports, with 245 of them being corporate customers.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Save changes to all open Word documents at one time

Microsoft Office Suite

If your Word sessions often wind up with a lot of open documents, this obscure command can streamline the process of closing them and saving your changes.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web