Klez ousted by MiMail as top virus

By Staff, ZDNet Australia
Friday, August 08, 2003 04:36 PM
The MiMail worm has snatched prime position away from Klez by becoming the fastest spreading Internet menace, according to mail filtering company MessageLabs.

The veteran Klez, which was discovered all the way back in April last year, has slipped to second position in only a week following MiMail's stunning debut as the Internet's new 'bad boy' on the block.

The company has detected 143,709 copies of MiMail since August one, but the 'all time high' prize will likely remain unchallenged for a while longer -- MessageLabs has seized 7,192,232 copies of Klez over the last 18 months or so.

Despite being far less complex than the Klez worm, which used network shares and e-mails to spread, the MiMail worm uses a social engineering technique to trick a user into opening an attachment.

The message is disguised as an announcement from the target's ISP administrator -- it invariably 'spoofs' the address 'admin@targetdomain.xxx'. The attachment itself is a HTML file that exploits a vulnerability in Internet Explorer -- it executes itself and begins to spread.

Far from ripping through corporate systems, both worms have been felt most by home users, says security consultant Daniel Lewkovitz.

"Most domestic users either don't realise that there's more to e-mail security than having up to date anti-virus," he told ZDNet Australia . "Things like Klez have all but disappeared in the corporate world but are still rampant out there."

He says getting the message across to the mums, dads and grandparents is tough -- they simply don't understand that they need to patch their systems.

According to its product security manager George Stathakopoulos, Microsoft is currently conducting an education campaign to better inform users of the risks of running software that isn't up to date, but is being careful not to force the message on people.

Anti-virus researcher Hamish O'Dea of Computer Associates says MiMail's infection rate will probably slip as time moves on.

ZDNet Australia reports from Sydney.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Keep IMAP e-mail messages locally using OfflineIMAP

Open Source

Vincent Danen discusses the uses of OfflineIMAP for synchronizing local and remote IMAP mailboxes and providing a good method for backing up e-mail.


Read more »



Buying a projector? Try an LED TV instead

Blog thumbnail

If you're thinking of buying a new projector for your office meeting room, why not consider getting an LED TV instead. LED TVs are similar to LCD TVs except..... by Lee Lup Yuen

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web