Worm sparks rise in zombie PCs

By Joris Evers and Colin Barker, CNET News.com
Wednesday, August 23, 2006 09:55 AM

Malicious code that exploits a recent Windows hole has led to significant growth in the number of hijacked PCs, according to messaging security company CipherTrust.

On Tuesday, CipherTrust reported a 23 percent growth in the total number of so-called zombie PCs it has detected. The jump is due to the spread of Mocbot worm variants, CipherTrust said. Mocbot, also known as Cuebot and Graweg, exploits a Windows security flaw for which Microsoft issued a patch with security bulletin MS06-040 on Aug. 8.

"Around Aug. 13, the weekend after Black Tuesday, we started seeing a gradual increase in the average number of new zombies," said Dmitri Alperovitch, a research scientist at CipherTrust in Alpharetta, Ga. "It went up from 214,000 every day in the previous week to 265,000 every day."

Any computer infected by Mocbot will become part of a botnet, a large network of compromised PCs that can be controlled remotely to carry out tasks such as sending spam. In June, Microsoft warned that the threat posed by botnets and zombies was growing fast.

CipherTrust can trace the increase in spam-sending zombies to Mocbot by comparing junk e-mail sent by systems it knows were compromised by the worm to the spam sent by new zombies, Alperovitch said. "They are mostly Rolex spam and porn spam, and they are the same messages that are being sent by these new zombies coming online," he said.

Alperovitch estimated that somewhere between 500,000 and 1 million machines were hijacked by Mocbot. As a result, more junk mail is soiling the Internet, with spam making up 81 percent of all mail volume this week. "I would not say this has been a huge outbreak, but it has been a noticeable change," he said.

Security experts had said that the MS06-040 worm appeared to be limited in its spread and only hitting computers running Windows 2000.

Colin Barker of ZDNet UK reported from London.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Changing the name of your SQL server

Enterprise Servers & Storage

When you change the name of a server you also have to change the name in SQL Server; if you don't, there may be problems.


Read more »



  • HPC Applications

    Ever wondered if High Performing Computing systems really matter in our day-to-day world? Let Dr David Scott from Intel take you a for quick tour on developing HPC applications.
    Play video


  • Maximize IT Spend: Business Acceleration

    How do you ensure your IT solutions are well integrated and streamlined across your enterprise? Rajen from Oracle highlights the important considerations ...
    Play video


  • HPC Architecture: Explained

    Why is High Performance Computing increasingly in demand in today's businesses? Find out which is the most widely deployed HPC architecture today.
    Play video

Tags

  1. apple
  2. attack
  3. attacks
  4. botnet
  5. credit
  6. data
  7. dns
  8. e-mail
  9. facebook
  10. fix
  11. flaw
  12. flaws
  13. fraud
  14. google
  15. iphone
  16. issues
  17. malware
  18. microsoft
  19. over
  20. patch
  21. researcher
  22. researchers
  23. security
  24. sites
  25. symantec
  26. team
  27. uk
  28. us
  29. users
  30. worm

Hooked on online banking

Blog thumbnail

Unlike in countries like Singapore and Hong Kong, where cashless transactions are already the norm, credit card purchases in the Philippines are still the exception rather than the rule.

This is..... by Melvin G. Calimag

Read more »